agent-native-repo-playbook
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation-centric tool designed to help agents audit repository structures (such as
AGENTS.mdanddocs/) and recommend improvements based on 'harness engineering' principles. It provides a structured rubric and scoring system for readiness audits. - [DATA_EXPOSURE]: The skill requires read access to local repository configuration files, including
.github/workflows/,AGENTS.md, and project documentation. This access is necessary for its stated purpose of auditing repository readiness and does not involve sending sensitive data to external domains. - [EXTERNAL_DOWNLOADS]: The skill references external articles from OpenAI and transcripts hosted on aipodcast.ing (a vendor-controlled domain associated with the author). These are informational resources and do not involve the execution of untrusted remote code.
- [PROMPT_INJECTION]: As an audit tool, the skill is subject to indirect prompt injection if the repository being audited contains malicious instructions in its documentation files. However, the skill implements a strict rubric and clear operating principles to ground the agent's analysis, and this risk is inherent to the auditing task.
Audit Metadata