nix-coding-protocol
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified as the skill is designed to process external technical data.
- Ingestion points: Source code, technical logs, configurations, and test files (as referenced in SKILL.md).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified.
- Capability inventory: The skill is capable of generating source code, automation scripts, and patch solutions.
- Sanitization: No specific input sanitization or validation logic is defined.
- [SAFE]: No hardcoded credentials, network operations, or external downloads were detected.
- [SAFE]: The skill definition is purely instructional and does not contain executable scripts.
- [SAFE]: The workflow explicitly includes a 'Risk Hint' phase that mandates the assessment of security and permission impacts.
Audit Metadata