testimonials-generator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown instructions and design documentation. There are no scripts (Python, JavaScript, Shell) or binaries included in the skill definition.\n- [SAFE]: No external URLs, remote resources, or network operations are referenced, eliminating risks associated with data exfiltration or malicious downloads.\n- [SAFE]: The skill does not perform any privileged operations, command execution, or persistence mechanisms.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read project context files (.claude/project-context.md, .cursor/project-context.md) to gather information about customer personas. While this involves ingesting external data, the skill has no dangerous capabilities (like network access or shell execution) that could be leveraged for an attack.\n
  • Ingestion points: Reads project-context files (SKILL.md)\n
  • Boundary markers: None\n
  • Capability inventory: None (no network, shell, or write capabilities detected)\n
  • Sanitization: None
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:08 PM
Security Audit — agent-trust-hub — testimonials-generator