zero-tech-debt

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely through local documentation and standard development tools already available in the environment (e.g., git, rg, fd). It provides a methodology rather than executable script code.
  • [COMMAND_EXECUTION]: The skill utilizes common command-line utilities (git, rg, fd, grep) for their intended purposes: searching text, finding files, and staging commits. These tools are scoped to the project environment and do not involve privilege escalation or obfuscated commands.
  • [PROMPT_INJECTION]: The instructions contain phrases like "Do NOT use for hotfixes" and "Final Rule," but these are legitimate architectural constraints designed to guide the AI's behavior within the scope of its task, not attempts to bypass safety filters or override the system prompt.
  • [DATA_EXFILTRATION]: There are no network operations, hardcoded credentials, or attempts to access sensitive files (e.g., .ssh, .aws, .env). The skill focuses exclusively on the logical structure of application code.
  • [REMOTE_CODE_EXECUTION]: No external scripts or packages are downloaded or executed. The skill does not include any dependency management files or remote URLs for script sourcing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 11:30 AM
Security Audit — agent-trust-hub — zero-tech-debt