pixel-art

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [No Code] (SAFE): The skill consists entirely of Markdown documentation and static validation rules (regex). No executable scripts (.py, .js, .sh) or binary files are included in the package.
  • [Indirect Prompt Injection] (SAFE): The skill defines patterns to analyze untrusted user code (JS, CSS, etc.). However, because the skill lacks capabilities for network access, file system modification, or command execution, this data ingestion surface presents no significant security risk.
  • [Data Exposure] (SAFE): No patterns were found indicating the exfiltration of sensitive data or access to private system files.
  • [Prompt Injection] (SAFE): The instructions in SKILL.md use standard role-definition and grounding techniques without attempting to bypass safety filters or override system constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:55 PM