accelint-security-best-practices
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE] (SAFE): The skill is composed entirely of Markdown documentation and reporting templates. No executable code files, such as Python, JavaScript, or shell scripts, are present in the provided files.
- [DATA_EXFILTRATION] (SAFE): No hardcoded secrets, sensitive file paths, or network-capable commands (e.g., curl, fetch, wget) were detected within the skill content.
- [PROMPT_INJECTION] (SAFE): The instructions are designed to improve the security posture of the agent's outputs and do not contain override markers, bypasses, or instructions to ignore safety filters.
- [INDIRECT_PROMPT_INJECTION] (SAFE): The skill is intended to process untrusted user code for auditing. Mandatory Evidence Chain: 1. Ingestion points: The skill accepts external code blocks via user prompts. 2. Boundary markers: Absent. 3. Capability inventory: No dangerous capabilities (file system writing, code execution, network access) exist within the skill. 4. Sanitization: Not implemented. Despite the ingestion surface, the lack of tool capabilities eliminates the risk of exploitation.
- [EXTERNAL_DOWNLOADS] (SAFE): While the skill links to external GitHub repositories in the README, these are informational references only and do not trigger automated downloads or remote code execution at runtime.
Audit Metadata