night-market-completion-integrity-campaign

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill outlines a comprehensive "Completion-Integrity Campaign" aimed at hardening autonomous agent loops against faked completion signals. The logic is focused on security auditing and improving system reliability.
  • [COMMAND_EXECUTION]: The skill includes several executable bash blocks that run unit tests using uv run pytest. These commands are localized to the repository's plugin directories (egregore, herald, imbue) and are used to establish baselines and verify code changes.
  • [COMMAND_EXECUTION]: The instructions use inline Python scripts (`python3
  • <<'EOF') to parse local .egregore/manifest.json` files. These scripts perform benign data aggregation to identify work items that may have bypassed quality gates, facilitating a "shadow observation" phase.
  • [DATA_EXFILTRATION]: Analysis of the skill reveals no unauthorized network operations or exfiltration of sensitive data. It references internal manifest files and session transcripts for local diagnostic purposes only.
  • [SAFE]: While the skill discusses persistence mechanisms like watchdog services and session relaunching, it does so to describe the existing architecture of the repository for the purpose of accurate debugging, rather than attempting to install new unauthorized persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 01:38 AM
Security Audit — agent-trust-hub — night-market-completion-integrity-campaign