human-feedback

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is local documentation management. It reads and writes to HUMAN.md and HUMAN_FRICTIONS.md within the project repository to track workflow improvements.
  • [PROMPT_INJECTION]: No patterns indicative of prompt injection, such as instructions to ignore safety guidelines or bypass constraints, were detected in the instructions or the schema.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain any patterns for downloading or executing remote code. It does not use package managers or dynamic execution functions like eval or exec.
  • [DATA_EXFILTRATION]: No network-related commands (e.g., curl, wget) or access to sensitive file paths (e.g., .ssh, .aws, .env) were found. The skill operates exclusively on project-specific feedback files.
  • [COMMAND_EXECUTION]: There is no evidence of shell command execution or attempts at privilege escalation. The skill limits its activities to structured text manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 05:16 AM
Security Audit — agent-trust-hub — human-feedback