cleared
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions define a legitimate development workflow for auditing project readiness. It does not contain any prompt injection, obfuscation, or malicious network patterns.
- [CREDENTIALS_UNSAFE]: The skill proactively addresses secret security by instructing the agent that environment variable "values never printed" and marking the presence of "committed secrets" as a blocking failure.
- [INDIRECT_PROMPT_INJECTION]: The skill handles external data (command outputs and project files) but mitigates potential injection risks by requiring the agent to quote outputs and verify dimensions against a specific set of predefined criteria and evidence sources.
Audit Metadata