clean-code
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a 'Verification Scripts' section that instructs the agent to execute specific Python auditing scripts (e.g.,
security_scan.py,api_validator.py,lint_runner.py) located in the agent's environment at~/.claude/skills/. This is a functional requirement for automated code quality validation. - [SAFE]: The skill implements a robust human-in-the-loop safety protocol ('Script Output Handling'). It explicitly forbids auto-fixing errors and mandates that the agent read script output, summarize it for the user, and wait for confirmation before taking action.
- [SAFE]: Analysis for Indirect Prompt Injection (Category 8) shows a well-managed attack surface. While the agent ingests untrusted data from script outputs and possesses file-write capabilities, the mandatory user review step acts as an effective sanitization and authorization boundary.
- [SAFE]: The instructions focus on standard software development best practices (SRP, DRY, KISS, YAGNI) and promote self-documenting code, which generally enhances the security and maintainability of the generated output.
Audit Metadata