spring-ai
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill content is limited to instructional markdown and code examples for the Spring AI library. It does not include any executable scripts, tool configurations, or automated commands.\n- [CREDENTIALS_UNSAFE]: The skill correctly uses environment variable placeholders such as
${OPENAI_API_KEY}and${ANTHROPIC_API_KEY}in its configuration examples, following secure development practices rather than hardcoding actual secrets.\n- [EXTERNAL_DOWNLOADS]: The Maven and Gradle dependency examples reference the officialorg.springframework.aigroup, which is the legitimate source for the Spring AI project. No untrusted or suspicious external package sources were found.\n- [PROMPT_INJECTION]: The example prompt templates and user message snippets are purely illustrative for developers and do not contain instructions aimed at bypassing agent safety filters or overriding system instructions.
Audit Metadata