bazdmeg

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of Markdown documentation and reference files. It does not contain any executable scripts, binaries, or active code components that could perform operations on the host system.
  • [NO_CODE]: There is no functional code or software package included with this skill. Its purpose is to provide structured natural language instructions and development checklists to guide the AI agent's reasoning.
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection by instructing the agent to prioritize local project files (e.g., CLAUDE.md, README, STATUS_WALKTHROUGH) as canonical specifications. Evidence: (1) Ingestion points: Checkpoint 0 in SKILL.md and the DOC-ANSWER Gate in references/08-sources-have-rank.md; (2) Boundary markers: No specific delimiters or safety warnings are defined for these ingested files; (3) Capabilities: The workflow assumes the agent has access to development tools like vitest and file system operations; (4) Sanitization: No validation or filtering is specified for the content of the project files.
  • [EXTERNAL_DOWNLOADS]: No remote URLs or external scripts are accessed or downloaded by the skill.
  • [COMMAND_EXECUTION]: The documentation references standard tools like vitest and git but does not contain commands to execute them directly or maliciously.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 01:10 AM