figure-it-out
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No prompt injection attempts or safety bypass instructions were detected. The instructions focus on establishing a scientific method for software development and ensuring human review.
- [DATA_EXFILTRATION]: No patterns of sensitive data access or exfiltration were found. The skill recommends creating a decision log in a TSV format and committing it to the project's version control for audit purposes, which is standard development practice.
- [REMOTE_CODE_EXECUTION]: The skill does not perform any remote code downloads or execution from untrusted sources. It relies on a local capability contract and specific adapters for the host environment.
- [COMMAND_EXECUTION]: While the skill mentions parallelizing work across branches or worktrees, these are standard git operations intended for managing complex development tasks. It uses abstracted capability verbs rather than direct shell commands.
- [INDIRECT_PROMPT_INJECTION]: The skill processes high-level user tasks to design workflows. While this represents a potential attack surface for indirect injection via malicious task descriptions, the skill mitigates this by requiring falsifiable predicates and human-auditable logs to verify all outcomes.
Audit Metadata