raw-app

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agent to execute CLI commands (wmill app new, wmill generate-metadata) to manage project files. It emphasizes using non-interactive flags to ensure compatibility with AI agents and explicitly requires user consent before performing potentially destructive operations such as overwriting local files or deploying to a workspace.
  • [PROMPT_INJECTION]: The provided instructions use imperative language to define the agent's operating procedures (e.g., forbidding guessing of parameters). These are legitimate workflow constraints designed to ensure task success and do not represent an attempt to bypass safety or ethical guidelines.
  • [SAFE]: The skill promotes privacy by instructing the agent to use the 'data-wm-no-record' attribute for sensitive UI elements, ensuring that customer data or internal notes are excluded from recorded sessions and demos.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 04:44 AM
Security Audit — agent-trust-hub — raw-app