graphicode-infra-init

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands such as mkdir, cat, and cp to set up project folders and configuration files. These actions are legitimate for a project initializer and do not target sensitive system areas.\n- [DATA_EXFILTRATION]: No network-based exfiltration or unauthorized file reads of sensitive system data (e.g., .env, SSH keys) were identified. The data usage is restricted to the initialization of graphig.md based on user-provided application names and environment choices.\n- [PROMPT_INJECTION]: The skill's instructions are procedural and focused on scaffolding. No patterns related to safety filter bypasses, instruction overrides, or adversarial role-playing were found.\n- [REMOTE_CODE_EXECUTION]: There is no evidence of downloading or executing scripts from external URLs. All code utility files are part of the skill's local asset directory.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 10:49 AM