software-clean-code-standard

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive reference for software engineering best practices, defining stable rule IDs (CC-*) for code quality, maintainability, and security hygiene. It covers topics like naming, functions, control flow, and error handling with a focus on long-term project health.
  • [EXTERNAL_DOWNLOADS]: The documentation and utility patterns reference various third-party libraries for different ecosystems, including Node.js (e.g., Argon2, Zod, Pino, OpenTelemetry), Python (e.g., Pydantic, structlog, tenacity), and Go (e.g., zap, gobreaker). These are well-established, industry-standard packages used to implement the recommended best practices. The external URLs provided in data/sources.json point to official documentation and trusted research sources (e.g., OWASP, NIST, Google, GitHub, Arxiv).
  • [COMMAND_EXECUTION]: The skill provides example commands for standard development workflows, such as running linters (eslint, ruff), type checkers (tsc, mypy), and package managers (npm, pip, go get). These operations are typical for a software development environment and are documented as part of quality assurance procedures.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private tokens were found in the skill. The references/config-validation.md file correctly identifies hardcoded secrets as a security anti-pattern and provides guidance on using environment variables and dedicated secrets management services (e.g., AWS Secrets Manager, HashiCorp Vault, Doppler).
  • [PROMPT_INJECTION]: The skill contains instructional content for code review and standards enforcement but does not include patterns aimed at overriding agent behavior or bypassing safety filters.
  • [DATA_EXFILTRATION]: No network operations or file access patterns indicative of unauthorized data collection or exfiltration were detected. The network utilities provided (e.g., resilience-utilities.md, llm-utilities.md) are designed for legitimate application functionality like API requests and observability.
  • [OBFUSCATION]: The skill content is clear and follows a standard markdown structure. No obfuscated code, zero-width characters, or hidden URLs were identified.
  • [DYNAMIC_EXECUTION]: The utility patterns provided show how to use standard libraries for runtime tasks like token counting or error handling, but they do not involve unsafe dynamic code generation or execution from untrusted sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — software-clean-code-standard