clean-code

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains a 'Verification Scripts' section that instructs the agent to execute specific Python auditing scripts (e.g., security_scan.py, api_validator.py, lint_runner.py) located in the agent's environment at ~/.claude/skills/. This is a functional requirement for automated code quality validation.
  • [SAFE]: The skill implements a robust human-in-the-loop safety protocol ('Script Output Handling'). It explicitly forbids auto-fixing errors and mandates that the agent read script output, summarize it for the user, and wait for confirmation before taking action.
  • [SAFE]: Analysis for Indirect Prompt Injection (Category 8) shows a well-managed attack surface. While the agent ingests untrusted data from script outputs and possesses file-write capabilities, the mandatory user review step acts as an effective sanitization and authorization boundary.
  • [SAFE]: The instructions focus on standard software development best practices (SRP, DRY, KISS, YAGNI) and promote self-documenting code, which generally enhances the security and maintainability of the generated output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — clean-code