skills/venhdev/skills/assay/Gen Agent Trust Hub

assay

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as an analytical framework for code review. It specifically includes security-positive instructions to identify 'unredacted secrets' and 'operational hygiene' issues in processed code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (code diffs, task breakdowns, and changesets). While this presents a theoretical injection surface where instructions could be embedded in code comments or diffs to influence the reviewer's output, the skill lacks the capabilities (file writing, command execution, or network access) required to translate such an injection into a security breach.
  • Ingestion points: SKILL.md Phase 1 (Ingests uncommitted diffs and staged changesets).
  • Boundary markers: Absent.
  • Capability inventory: None detected; the skill is constrained to analysis and reporting.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:52 AM
Security Audit — agent-trust-hub — assay