loom-plan-writer
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill incorporates security best practices by instructing agents to ask users about sandbox requirements, specifically identifying sensitive paths (SSH keys, AWS configs, environment files) to be protected via deny_read and deny_write rules.
- [COMMAND_EXECUTION]: The skill guides the agent in writing execution plans that contain shell commands for verification (acceptance, truths, wiring). These commands are standard development tools (e.g., cargo, rg, grep) and are necessary for the skill's primary purpose of orchestration and verification.
- [DATA_EXPOSURE]: While the skill references sensitive file paths (e.g., ~/.ssh, ~/.aws), it does so in the context of configuring a sandbox to prevent unauthorized access by other agents, which is a defensive measure.
Audit Metadata