idea-refine

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill implements a robust brainstorming framework using local resources and clearly defined instructions for the agent's role as an ideation partner.
  • [SAFE]: The skill includes a shell script ('scripts/idea-refine.sh') used to initialize a document directory. The script performs basic filesystem checks and directory creation without using elevated privileges or dangerous commands.
  • [SAFE]: The skill possesses a surface for indirect prompt injection as it is designed to ingest codebase context using search and read tools to provide relevant brainstorming assistance. This behavior is considered safe as it aligns with the skill's primary purpose and relies on standard platform capabilities. Evidence chain: 1. Ingestion points: The agent is instructed in SKILL.md to use Glob, Grep, and Read tools to scan for architectural context. 2. Boundary markers: No specific delimiters or safety instructions are defined for the ingested data. 3. Capability inventory: The skill allows the agent to generate and save markdown artifacts to a user-confirmed directory. 4. Sanitization: No explicit sanitization of codebase content is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 01:31 PM
Security Audit — agent-trust-hub — idea-refine