avalonia-layout-zafiro

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION] (SAFE): No malicious instructions or bypass attempts were detected in the skill's markdown or metadata. The 'Selective Reading Rule' is a benign operational instruction.
  • [DATA_EXFILTRATION] (SAFE): No hardcoded credentials, sensitive file access patterns, or network communication tools (like curl or wget) are present. The reference to the 'Angor' project path is for developer context.
  • [REMOTE_CODE_EXECUTION] (SAFE): The skill does not download external scripts or packages. It is entirely documentation-based.
  • [COMMAND_EXECUTION] (SAFE): No shell commands or system-level modification instructions are included.
  • [INDIRECT_PROMPT_INJECTION] (SAFE): The skill defines a surface for processing user-provided layout files with file-system write capabilities, but does not contain exploitable patterns.
  • Ingestion points: User-provided XAML/C# code files or layout descriptions entering via the agent's tool-use context (Read/Write/Edit).
  • Boundary markers: Absent; the guidelines do not specify delimiters for external content.
  • Capability inventory: File system access via 'Read', 'Write', 'Edit', 'Glob', and 'Grep' tools.
  • Sanitization: Absent; the skill relies on the AI agent's underlying safety layer for input validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:34 PM