light-self-review

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation references several well-known security and data validation services, including Snyk, Socket.dev, Deepchecks, and Evidently. These are used as reference tools for the agent to verify dependency safety and data integrity.
  • [COMMAND_EXECUTION]: The skill's 'evidence gate' protocol mandates the execution of local verification tools (such as pytest or security scanners like mcp-scanner) to provide objective proof of task completion. These commands are part of the intended functional process for output verification.
  • [SAFE]: The skill includes specific checks for identifying prompt injection and data exfiltration in other tasks, demonstrating an 'assume-malicious' security posture for its internal auditing functions.
  • [SAFE]: The instructions and references originate from or point to reputable sources and established projects (e.g., Cisco's AI Defense tools, the obra/superpowers community skills), focusing on improving reliability and safety through structured review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 08:01 AM
Security Audit — agent-trust-hub — light-self-review