developer-growth-analysis
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWNO_CODE
Full Analysis
- [NO_CODE] (LOW): The submission only includes the
metadata.jsonfile. The referenced logic and instructions inSKILL.mdare absent, preventing an evaluation of command execution, data handling, or potential obfuscation.\n- [DATA_EXFILTRATION] (INFO): The metadata description indicates that the skill is designed to read private Claude Code chat history and transmit data to Slack. This specific capability (sensitive read + network write) constitutes a high-risk surface for data exfiltration that must be verified against the missing implementation.\n- [PROMPT_INJECTION] (INFO): According to the metadata, the skill ingests content from HackerNews. This ingestion of external, untrusted data creates a vulnerability surface for indirect prompt injection, which can only be assessed by reviewing the prompt delimiters and sanitization logic in the primary skill file.
Audit Metadata