model-supply-chain
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly defensive in nature, providing a methodology for engineers to identify risks like model poisoning and insecure serialization in their own systems.
- [SAFE]: The skill includes a 'Prompt Injection Safety Notice' that explicitly instructs the agent to ignore any commands or behavioral overrides found in the files under review, mitigating risks of indirect prompt injection.
- [SAFE]: Resource access is restricted via the
allowed-toolsconfiguration toRead,Grep, andGlob. This scope limitation prevents the skill from performing network operations, writing files, or executing arbitrary system commands. - [SAFE]: No evidence of obfuscation, hidden URLs, remote code execution patterns, or unauthorized persistence mechanisms was found within the instructions or metadata.
Audit Metadata