why-review-loop
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill implements a structured workflow for automated code review and improvement with multiple safety gates.
- [PROMPT_INJECTION]: The skill uses instructional framing to ensure the agent adheres to a specific execution protocol (e.g., "Strict execution contract", "Do not skip, reorder, or merge protocol steps"). These instructions are designed to ensure consistency and transparency in a multi-step workflow rather than bypassing safety filters.
- [DATA_EXFILTRATION]: The skill contains explicit security policies to prevent data leakage, including a mandate to "NEVER store secrets, tokens, credentials, or private customer data in goal files" and a requirement that the agent "Do NOT commit or push unless the user explicitly asks."
- [COMMAND_EXECUTION]: The skill manages file modifications through other tools (like
$fix), but implements a mandatory "Trade-Off Gate." This gate requires the agent to analyze the consequences of every fix and forces a pause to ask the user for confirmation if a change is material, irreversible, or crosses security boundaries.
Audit Metadata