skills/xiaolai/nlpm/rules/Gen Agent Trust Hub

rules

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown text and rules. It does not contain any executable scripts, binary files, or automated commands that could pose a risk to the host system.
  • [PROMPT_INJECTION]: The skill includes security-positive rules (Rule R42) explicitly teaching the agent to resist prompt injection by treating user-provided content as data rather than instructions. It also provides guidelines for establishing clear mission boundaries.
  • [DATA_EXFILTRATION]: No network exfiltration patterns or sensitive file access commands were found. The skill does not include any tools or instructions that would move data outside of the local environment.
  • [PRIVILEGE_ESCALATION]: The skill promotes secure development practices (Rule R11) by requiring that tools follow the principle of least-privilege, specifically flagging excessive permissions as a 'security smell.'
  • [EXTERNAL_DOWNLOADS]: All references to external examples use relative local file paths within the project structure (e.g., ../../../auditor/exemplars/). There are no attempts to download code or data from untrusted remote servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:56 PM
Security Audit — agent-trust-hub — rules