ralph-wiggum-v2

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the project codebase during the review swarm and TDD cycle.\n
  • Ingestion points: Codebase files within the {project} directory and findings generated by spawned review agents.\n
  • Boundary markers: Absent; instructions do not include specific delimiters for untrusted code content.\n
  • Capability inventory: The skill has the capability to write files (implementing fixes), run test suites, and generate production builds.\n
  • Sanitization: Absent; agent findings and code fixes are implemented without a verification or filtering step for malicious patterns.\n- [DYNAMIC_EXECUTION]: The skill automates the generation and execution of code within the project environment.\n
  • The workflow involves writing new tests and minimal fixes based on findings, then executing these scripts alongside the project's existing test suite and build processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:55 AM
Security Audit — agent-trust-hub — ralph-wiggum-v2