readiness-audit

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The evaluation script eval/run_harness.py utilizes subprocess.run to manage test execution within Docker containers. This implementation is designed with security in mind, requiring SHA-256 digest verification for external runner executables and mandatory digest pinning for Docker images to ensure supply chain integrity.
  • [DATA_EXFILTRATION]: The skill's instructions in SKILL.md contain explicit guardrails that prohibit the agent from implying or claiming access to non-public data (such as Search Console, revenue, or analytics) unless the user has explicitly provided verified exports. This enforces a 'public-signals-only' policy for the audit process.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process external HTML storefront data, the instructions establish clear boundary markers and scoring rubrics. The evaluation harness further mitigates risk by running trials in network-isolated (--network none) and read-only environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 12:13 PM
Security Audit — agent-trust-hub — readiness-audit