platform-engineer
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [Prompt Injection] (SAFE): The skill contains no instructions attempting to override agent behavior, bypass safety filters, or extract system prompts.
- [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file paths, or network exfiltration patterns were detected. The examples use dummy placeholders for infrastructure configuration.
- [Remote Code Execution & Dependencies] (SAFE): The skill does not perform any remote script downloads or unverifiable package installations. It mentions standard tools (Backstage, Crossplane, MkDocs) but does not provide commands to install them.
- [Command Execution & Privilege Escalation] (SAFE): There are no shell commands, subprocess calls, or attempts to acquire administrative privileges.
- [Persistence & Obfuscation] (SAFE): No persistence mechanisms (like cron jobs or shell profile modifications) or obfuscated content (like Base64 or hidden characters) are present.
- [Indirect Prompt Injection] (SAFE): While the skill discusses processing developer templates and manifests, it contains no code or active capabilities that would ingest and execute instructions from untrusted external data.
Audit Metadata