why-review-loop

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill implements a structured workflow for automated code review and improvement with multiple safety gates.
  • [PROMPT_INJECTION]: The skill uses instructional framing to ensure the agent adheres to a specific execution protocol (e.g., "Strict execution contract", "Do not skip, reorder, or merge protocol steps"). These instructions are designed to ensure consistency and transparency in a multi-step workflow rather than bypassing safety filters.
  • [DATA_EXFILTRATION]: The skill contains explicit security policies to prevent data leakage, including a mandate to "NEVER store secrets, tokens, credentials, or private customer data in goal files" and a requirement that the agent "Do NOT commit or push unless the user explicitly asks."
  • [COMMAND_EXECUTION]: The skill manages file modifications through other tools (like $fix), but implements a mandatory "Trade-Off Gate." This gate requires the agent to analyze the consequences of every fix and forces a pause to ask the user for confirmation if a change is material, irreversible, or crosses security boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — why-review-loop