skills/xiaolai/nlpm/scoring/Gen Agent Trust Hub

scoring

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely composed of documentation, guidelines, and reference examples for artifact scoring. It does not perform any file system operations, network requests, or command executions.
  • [COMMAND_EXECUTION]: The rubric includes references to potentially dangerous shell commands (e.g., rm -rf, DROP TABLE) solely as examples of patterns that a security auditor should detect and penalize in other projects. These are not executed by the skill.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: While the rubric instructs agents to check for hardcoded secrets in settings files, it does not contain or transmit any sensitive information itself.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for analyzing external content (artifacts). However, as it is a static set of instructions without tool-based capabilities, it does not present a vulnerability surface for indirect injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:57 PM
Security Audit — agent-trust-hub — scoring