dev-context-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The core objective of the skill is to improve agent safety and alignment through Context Engineering. It provides governance templates (assets/ai-agent-governance.md) that define approved tools and usage restrictions.
  • [COMMAND_EXECUTION]: The skill includes Python scripts (scripts/scan_context_artifacts.py, scripts/validate_context_graph.py, scripts/query_context_graph.py) that scan the local filesystem to identify context artifacts and relationships. These scripts do not perform network requests, use dynamic execution, or require elevated privileges.
  • [EXTERNAL_DOWNLOADS]: External resources cited in the skill (e.g., GitHub Spec Kit, Anthropic documentation, industry research) are informational and originate from trusted and well-known technology entities. The skill does not automate the download or execution of these external resources.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes repository files (AGENTS.md, rule files) which could theoretically contain malicious instructions, the provided framework is designed to sanitize and govern these inputs. The skill implements detection and validation logic to manage context maturity and consistency rather than executing file contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:35 AM
Security Audit — agent-trust-hub — dev-context-engineering