rubber-duck
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external code and documentation which could contain malicious instructions. This risk is addressed by explicit security guidelines in both the main skill and the subagent prompt that instruct the agent to treat all reviewed material as data only and to disregard any instructions contained within it.
- [DATA_EXPOSURE]: The skill follows security best practices by explicitly instructing the agent to redact secrets, credentials, and tokens before pasting implementation details into the review request.
- [COMMAND_EXECUTION]: The skill does not perform any direct command execution or file system modifications. It is a text-based coordination skill for independent validation.
Audit Metadata