figure-it-out

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a meta-process for designing workflows for ambitious changes, focusing on rigor and auditability without any malicious commands.
  • [PROMPT_INJECTION]: No evidence was found of instructions attempting to bypass safety protocols or override core agent behaviors.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local files (e.g., credentials) or perform unauthorized network requests to external domains.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts from untrusted sources.
  • [COMMAND_EXECUTION]: While the skill encourages the use of scripts for verification and evidence, it does not execute arbitrary shell commands or provide a path for user-controlled command injection.
  • [SAFE]: The skill identifies a standard indirect prompt injection surface through the processing of workspace artifacts, but explicitly mitigates this risk by requiring the agent to audit artifacts and verify results against real products rather than relying on self-reports.
  • Ingestion points: Processes workspace files ('artifacts') during the verification loop in Phase C.
  • Boundary markers: None explicitly defined for raw artifact content, though process boundaries are clear.
  • Capability inventory: Performs file writes (logs/audit trails) and executes local scripts for verification (Phase D).
  • Sanitization: Includes explicit instructions to audit delegate artifacts and verify results through direct inspection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 05:53 PM
Security Audit — agent-trust-hub — figure-it-out