constitution-first

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown instructions and documentation. It does not contain any scripts, binaries, or executable configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface for indirect prompt injection as it instructs the agent to read existing project documentation like READMEs or vision statements.
  • Ingestion points: Reads existing project files such as 'manifesto', 'VISION', or 'README' (SKILL.md, Operating Order Step 1).
  • Boundary markers: No explicit instructions are provided to the agent to treat external file content as untrusted or to use delimiters.
  • Capability inventory: The skill involves writing new markdown files (Step 4) and updating agent instructions (Step 6), but contains no subprocess calls, network operations, or code execution capabilities.
  • Sanitization: No sanitization or validation of the ingested documentation content is performed.
  • [SAFE]: No malicious patterns, obfuscation, data exfiltration attempts, or unauthorized command executions were detected. The skill's behavior is consistent with its stated purpose of product documentation governance.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 09:44 PM
Security Audit — agent-trust-hub — constitution-first