scoring
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of documentation, guidelines, and reference examples for artifact scoring. It does not perform any file system operations, network requests, or command executions.
- [COMMAND_EXECUTION]: The rubric includes references to potentially dangerous shell commands (e.g.,
rm -rf,DROP TABLE) solely as examples of patterns that a security auditor should detect and penalize in other projects. These are not executed by the skill. - [DATA_EXPOSURE_AND_EXFILTRATION]: While the rubric instructs agents to check for hardcoded secrets in settings files, it does not contain or transmit any sensitive information itself.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for analyzing external content (artifacts). However, as it is a static set of instructions without tool-based capabilities, it does not present a vulnerability surface for indirect injection attacks.
Audit Metadata