audit-context-building

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists primarily of markdown documentation and instructional guidelines (SKILL.md, ANALYSIS_FORMAT.md, DOMAIN_NOTES.md, etc.) used to direct an LLM in performing systematic code reviews.
  • [NO_CODE]: No executable scripts (Python, JavaScript, Shell) are included in the skill package. All logic is expressed as natural language instructions for an AI agent.
  • [COMMAND_EXECUTION]: The skill mentions tools like 'Grep' and 'Read' in the allowed-tools frontmatter, but these are standard platform-provided tools used for searching and reading the codebase being audited, and no dangerous command sequences are present.
  • [DATA_EXFILTRATION]: No network operations or external URL references are present in the instructions. The analysis is designed to write findings to the local disk (audit-context/DOSSIER.md).
  • [PROMPT_INJECTION]: The instructions do not contain attempts to override safety filters or bypass system constraints. They focus on maintaining an objective analysis posture where results are recorded without assigning severity or suggesting fixes prematurely.
  • [TRUST_SCOPE_RULE]: The assets and agent configuration provided by 'trailofbits' use standard vendor resource patterns and contain no suspicious elements.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:33 PM
Security Audit — agent-trust-hub — audit-context-building