onboarding

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill manages sensitive information (SDK keys, API tokens) by instructing the agent to use environment variables and .env files, specifically avoiding hardcoded credentials. It includes explicit 'BLOCKING' decision points that require user consent before fetching or writing secrets.
  • [SAFE]: Repository modifications, such as installing packages or writing configuration files, are preceded by planning steps and user approval checkpoints (e.g., D6 for plan approval, D8 for dependency changes).
  • [SAFE]: External resources, including companion skills and SDK packages, are sourced from the author's official GitHub repositories (launchdarkly/ai-tooling) and recognized package registries.
  • [SAFE]: The skill provides security-conscious guidance, such as advising users to add configuration files containing tokens to .gitignore to prevent accidental exposure.
  • [SAFE]: Analysis of all 10 threat categories, including prompt injection, obfuscation, and privilege escalation, revealed no malicious patterns or bypass attempts. The instructional language used for 'Agent Behavior Directives' is standard for complex workflow orchestration.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 04:20 PM