agent-native-repo-playbook

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation-centric tool designed to help agents audit repository structures (such as AGENTS.md and docs/) and recommend improvements based on 'harness engineering' principles. It provides a structured rubric and scoring system for readiness audits.
  • [DATA_EXPOSURE]: The skill requires read access to local repository configuration files, including .github/workflows/, AGENTS.md, and project documentation. This access is necessary for its stated purpose of auditing repository readiness and does not involve sending sensitive data to external domains.
  • [EXTERNAL_DOWNLOADS]: The skill references external articles from OpenAI and transcripts hosted on aipodcast.ing (a vendor-controlled domain associated with the author). These are informational resources and do not involve the execution of untrusted remote code.
  • [PROMPT_INJECTION]: As an audit tool, the skill is subject to indirect prompt injection if the repository being audited contains malicious instructions in its documentation files. However, the skill implements a strict rubric and clear operating principles to ground the agent's analysis, and this risk is inherent to the auditing task.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 04:18 PM
Security Audit — agent-trust-hub — agent-native-repo-playbook