skills/b4r7x/nuke-skills/nuke-fix/Gen Agent Trust Hub

nuke-fix

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a structured process for running standard development tools (such as npm test, pytest, mypy, ruff, eslint, cargo test, and go vet) as part of its "Gates" validation architecture. These are legitimate uses of shell execution for code quality assurance.
  • [PROMPT_INJECTION]: The instructions include robust internal operational mandates, such as the requirement that "Implementers never validate their own work" and strict tier-based model assignments. these serve as process-level guardrails to maintain agent focus and prevent role confusion.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (e.g., fix-spec.md). It implements comprehensive mitigations against potential injection by requiring mechanical acceptance criteria (commands, tests, or quoted lines) and a mandatory re-validation wave by fresh subagents of a higher capability tier.
  • [DATA_EXFILTRATION]: The skill specifically prohibits automated git operations (git add, git commit) and the creation of backup files, ensuring that all changes are confined to the local working tree for human review and preventing silent credential or data theft via repository history.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 06:23 PM
Security Audit — agent-trust-hub — nuke-fix