NYC

accelint-security-best-practices

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE] (SAFE): The skill is composed entirely of Markdown documentation and reporting templates. No executable code files, such as Python, JavaScript, or shell scripts, are present in the provided files.
  • [DATA_EXFILTRATION] (SAFE): No hardcoded secrets, sensitive file paths, or network-capable commands (e.g., curl, fetch, wget) were detected within the skill content.
  • [PROMPT_INJECTION] (SAFE): The instructions are designed to improve the security posture of the agent's outputs and do not contain override markers, bypasses, or instructions to ignore safety filters.
  • [INDIRECT_PROMPT_INJECTION] (SAFE): The skill is intended to process untrusted user code for auditing. Mandatory Evidence Chain: 1. Ingestion points: The skill accepts external code blocks via user prompts. 2. Boundary markers: Absent. 3. Capability inventory: No dangerous capabilities (file system writing, code execution, network access) exist within the skill. 4. Sanitization: Not implemented. Despite the ingestion surface, the lack of tool capabilities eliminates the risk of exploitation.
  • [EXTERNAL_DOWNLOADS] (SAFE): While the skill links to external GitHub repositories in the README, these are informational references only and do not trigger automated downloads or remote code execution at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:11 PM