verification-loop
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes standard shell commands to execute development tasks such as project building (
npm run build,pnpm build), type checking (npx tsc,pyright), and linting (ruff). These are routine operations within a developer agent's environment. - [DATA_EXPOSURE]: The skill includes instructions to search the local codebase for potential hardcoded secrets using
grep(e.g., searching for patterns likesk-orapi_key). This is a defensive security practice intended for local verification and does not involve exfiltrating data to external services. - [SAFE]: No malicious patterns such as obfuscation, remote code execution from untrusted sources, persistence mechanisms, or unauthorized data exfiltration were detected. The skill's behavior is consistent with its stated purpose of providing a verification loop for code changes.
Audit Metadata