creating-agents

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The workflows in workflows/audit-agent.md and workflows/improve-agent.md instruct the agent to use standard shell commands like ls and cat to manage files in the ~/.claude/agents/ and .claude/agents/ directories. This is necessary for the skill's core functionality of auditing and managing agent definitions.\n- [DATA_EXFILTRATION]: While the skill accesses sensitive agent configuration files, it does not contain any instructions or patterns to exfiltrate this data. There are no network operations targeting external or untrusted domains.\n- [PROMPT_INJECTION]: The skill uses structural markers and prescriptive language to guide agent behavior but does not contain patterns meant to bypass safety filters or override system instructions. In fact, it explicitly teaches how to implement effective constraints in sub-agents.\n- [EXTERNAL_DOWNLOADS]: No external downloads, package installations, or remote script execution patterns were detected. All resources are locally contained within the skill package.\n- [REMOTE_CODE_EXECUTION]: The skill does not employ any dynamic code execution or remote command execution techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 10:17 PM