ai-agents
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is primarily a documentation repository and template library for architecting secure and observable AI agents. It incorporates extensive security guidance, including multi-layer guardrails and NIST AI RMF compliance checks.
- [NO_CODE]: Most of the 66 files are Markdown documentation, YAML configurations, or structured templates that do not contain executable logic.
- [SAFE]: The Python utility scripts (
agent_eval_runner.py,claude-usage.py,codex-usage.py) are designed for offline evaluation and usage tracking. They process local logs from Claude Code and OpenAI Codex to estimate costs and evaluate accuracy without making network requests or accessing unauthorized sensitive files. - [INDIRECT_PROMPT_INJECTION]: The skill describes architectures for agents that process untrusted data (such as RAG and tool-using agents). However, it defines these as vulnerability surfaces and provides clear operational patterns for mitigation, such as input validation, output filtering, and explicit boundary markers (e.g.,
<retrieved>tags).
Audit Metadata