loopy

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches verified loop templates from the vendor's official infrastructure at signals.forwardfuture.com.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface. Ingestion points: Reads untrusted data from codebases, threads, and external loops (SKILL.md, references/run.md). Boundary markers: Instructs the agent to treat data as passive evidence and ignore embedded overrides. Capability inventory: Executes scoped actions and makes network calls. Sanitization: Implements an 'audit' workflow to detect unsafe loop designs.
  • [COMMAND_EXECUTION]: Executes actions defined in workflows. This is governed by 'Run' rules requiring state verification and human approval for sensitive actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 10:00 AM
Security Audit — agent-trust-hub — loopy