poteto-mode
Pass
Audited by Gen Agent Trust Hub on Jul 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill is designed to enhance an AI agent's software engineering capabilities through structured playbooks and design principles.
- [DATA_EXFILTRATION]: The skill includes explicit security-conscious instructions in
playbooks/eval.mdandplaybooks/session-pickup.mdthat warn the agent against accessing files or transcripts in other project workspaces (e.g.,~/.cursor/projects/*/). This prevents accidental or intentional data leakage across project boundaries. - [COMMAND_EXECUTION]: The skill leverages standard platform tools (MCP, GitHub CLI, and specialized 'control' skills for UI/CLI testing) to perform legitimate development tasks such as reproduction of bugs, performance measurement, and pull request management.
- [PROMPT_INJECTION]: While the skill contains instructions that grant high autonomy ('Just do it', 'Never block on the human'), these are scoped to development tasks and are accompanied by instructions to pause for irreversible or high-risk actions, representing a balanced approach to agent autonomy rather than an attempt to bypass safety filters.
Audit Metadata