article-prompts-to-skills

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions include usage of local git commands (git status, git diff) to manage repository state and ensure narrow commits. This is a standard and expected behavior for a developer-oriented skill intended to manage a codebase.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly includes a security best-practice step (Step 7.8) to scan changed files for secrets, tokens, and private client data before committing, demonstrating a proactive security posture.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for external content (articles, tutorials, or prompt packs) which it processes to generate new instructions. While this represents a theoretical surface for indirect injection if the source material contains malicious instructions, the skill defines clear boundaries for extraction and focuses on mechanism over branding, which helps mitigate accidental obedience to source-specific editorializing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:12 AM
Security Audit — agent-trust-hub — article-prompts-to-skills