deck-wizard

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill enforces a mandatory verification process called the 'Iron Rule,' which requires the agent to lookup every card's official oracle text via the Scryfall API, preventing reliance on potentially inaccurate training data or untrusted external inputs.\n- [SAFE]: External data downloads for card bulk data and comprehensive rules are targeted at well-known and reputable community services such as Scryfall, which are considered safe for this domain.\n- [SAFE]: The analysis phase includes a 'Self-Grill' step that utilizes two separate agent instances to debate and verify the proposed deck changes, serving as a strategic safeguard against errors.\n- [SAFE]: The skill includes mechanical gates (legality-audit, mana-audit, price-check) to verify deck validity and budget compliance before presenting options to the user.\n- [SAFE]: All identified Python dependencies are standard, well-maintained packages from the official PyPI registry, and no suspicious remote code execution or persistence mechanisms were found.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 01:39 AM
Security Audit — agent-trust-hub — deck-wizard