agency-reality-checker

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run local shell commands (ls, grep) and a local shell script (./qa-playwright-capture.sh) to validate the project's build and capture screenshots for visual testing against localhost:8000.
  • [DATA_EXFILTRATION]: All data processing is confined to local project files and directories (e.g., resources/views/, public/qa-screenshots/). There are no external network requests or attempts to move sensitive data outside the environment.
  • [PROMPT_INJECTION]: The skill uses strong language to define a skeptical testing persona and instructions to disregard high ratings from other agents. These instructions are within the scope of the skill's intended purpose and do not attempt to bypass safety guardrails.
  • [PROMPT_INJECTION]: Mandatory Category 8 Analysis: 1. Ingestion points: The agent reads local HTML, CSS, and Blade files, and a test results JSON file (SKILL.md). 2. Boundary markers: None present. 3. Capability inventory: Local shell execution and local script invocation (SKILL.md). 4. Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-reality-checker