simplify-work

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were identified. The skill defines a process for code simplification that adheres to engineering best practices and emphasizes safety and correctness. The instructions prioritize correctness and safety above repository conventions or standard heuristics.\n- [PROMPT_INJECTION]: While the skill processes untrusted repository content (indirect prompt injection surface), it includes robust mitigations. It instructs the agent to confirm boundaries, trace data flow, and use an independent reviewer to verify claims against primary evidence. \n
  • Ingestion points: Reads repository instructions, documentation, and workspace files for simplification (SKILL.md).\n
  • Boundary markers: Explicitly mandates confirming the bounded surface, caller constraints, and proof before editing.\n
  • Capability inventory: Capable of reading/writing workspace files and invoking review tools.\n
  • Sanitization: Referenced guidelines (engineering-discipline.md) explicitly advise parsing untrusted input into valid internal data at external boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 03:47 AM
Security Audit — agent-trust-hub — simplify-work