download-export-safety
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional and designed to assist in auditing client-side code for export-related vulnerabilities. It does not include any executable scripts, remote code downloads, or persistence mechanisms.
- [DATA_EXPOSURE]: The skill provides ripgrep (
rg) commands for auditors to find sensitive strings (e.g., tokens, passwords, PII) within a codebase that might be inadvertently included in exports. This is a legitimate security auditing practice and does not involve exfiltration of data by the skill itself. - [EXTERNAL_DOWNLOADS]: The skill references authoritative external resources from OWASP and MDN regarding CSV injection and browser APIs. These are well-known, trusted documentation sources used for informational purposes.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided code for review (an ingestion point), it establishes clear boundaries and explicit review workflows to minimize the risk of malicious code influencing the agent's behavior. The provided analysis framework prevents accidental obedience by requiring strict evidence-based findings.
Audit Metadata