skills/juxt/claude-plugins/allium/Gen Agent Trust Hub

allium

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a significant attack surface for indirect prompt injection as it is designed to ingest and process untrusted external data, including user goals, feature descriptions, and existing implementation source code (SKILL.md, recommended-loops.md). The skill mitigates this through a 'witness' protocol that independently verifies ground truth and an autonomous ledger to track state transitions (driving-the-loop.md).
  • [DYNAMIC_EXECUTION]: The skill generates and facilitates the execution of test suites dynamically based on formal specifications (test-generation.md). While this involves generating executable content, it is the primary intended function of the behavioral specification tool and is gated by verification checks (driving-the-loop.md).
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to discover and execute local project test commands (e.g., framework runners) to verify code convergence (driving-the-loop.md). This is a standard capability for developer-centric tools and is performed within the scope of the user's project environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 07:24 PM