context-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of instructional guidelines and markdown templates intended to help users and agents structure their work sessions effectively. It does not contain executable code, scripts, or malicious commands.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill promotes security best practices by explicitly instructing the agent to 'Never commit .env files or secrets' in its template configurations.
- [INDIRECT_PROMPT_INJECTION]: It contains defensive guidance for handling untrusted data, specifically advising agents to treat imperative content from external sources as data rather than instructions to be followed.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts. References to external tools (MCP servers) are standard integrations and not part of the skill's own execution logic.
Audit Metadata