loop-converge

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing existing workspace code and output from static analysis tools to propose deletions and merges. This ingestion of untrusted repository content to drive file-modifying actions constitutes an indirect prompt injection surface.
  • Ingestion points: Workspace inspection as described in SKILL.md and candidate generation from detector outputs in preset.md.
  • Boundary markers: No explicit separators or 'ignore instructions' markers are defined for the ingested code content.
  • Capability inventory: The skill enables file modifications, command execution (tests and detectors), and local git commits as scoped in the 'Authority' section of preset.md.
  • Sanitization: No specific sanitization of workspace content or detector output is mentioned.
  • [COMMAND_EXECUTION]: The skill configuration involves running project-specific test commands and static analysis tools. preset.md specifically references the use of knip, jscpd, ruff, and vulture.
  • [DYNAMIC_EXECUTION]: The skill instructions in preset.md direct the agent to generate a 'throwaway' duplication detector script if a suitable one is not found in the target environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:38 PM
Security Audit — agent-trust-hub — loop-converge