skills/peiiii/nextclaw/project-os/Gen Agent Trust Hub

project-os

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes standard project maintenance commands (e.g., pnpm build, pnpm lint, git commit) and local filesystem operations (cp) for environment setup. These activities are transparently documented and consistent with the skill's stated purpose of project orchestration.\n- [PROMPT_INJECTION]: The skill establishes behavioral rules, including a mandatory reply prefix and a specific persona (CEO+CTO), to enforce compliance with the Rulebook. These are benign prompt engineering techniques used for agent governance rather than attempts to circumvent safety filters or override system constraints.\n- [CREDENTIALS_UNSAFE]: References to npm authentication via .npmrc and environment variables follow standard, secure development practices for managing package registry access. No hardcoded secrets or patterns indicating credential theft were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 09:42 PM