graphicode-infra-init
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands such as
mkdir,cat, andcpto set up project folders and configuration files. These actions are legitimate for a project initializer and do not target sensitive system areas.\n- [DATA_EXFILTRATION]: No network-based exfiltration or unauthorized file reads of sensitive system data (e.g.,.env, SSH keys) were identified. The data usage is restricted to the initialization ofgraphig.mdbased on user-provided application names and environment choices.\n- [PROMPT_INJECTION]: The skill's instructions are procedural and focused on scaffolding. No patterns related to safety filter bypasses, instruction overrides, or adversarial role-playing were found.\n- [REMOTE_CODE_EXECUTION]: There is no evidence of downloading or executing scripts from external URLs. All code utility files are part of the skill's local asset directory.
Audit Metadata