link-validation

Pass

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run lychee, a command-line utility for link validation. This operation is restricted to the workspace environment.
  • [EXTERNAL_DOWNLOADS]: The skill mentions external dependencies including lychee and uv. These are widely used developer tools. References point to official documentation on GitHub, which is a trusted platform.
  • [DATA_EXFILTRATION]: Outbound network requests are performed by lychee to verify URLs found in markdown files. This behavior is the primary intended function of the skill and does not involve the unauthorized transmission of sensitive data.
  • [PROMPT_INJECTION]: The skill includes a 'Self-Evolving Skill' section that directs the agent to update its own instruction file when encountering reproducible issues. This is a maintenance mechanism and does not contain patterns intended to bypass safety filters or override core agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 4, 2026, 09:51 AM