light-self-review
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation references several well-known security and data validation services, including Snyk, Socket.dev, Deepchecks, and Evidently. These are used as reference tools for the agent to verify dependency safety and data integrity.
- [COMMAND_EXECUTION]: The skill's 'evidence gate' protocol mandates the execution of local verification tools (such as
pytestor security scanners likemcp-scanner) to provide objective proof of task completion. These commands are part of the intended functional process for output verification. - [SAFE]: The skill includes specific checks for identifying prompt injection and data exfiltration in other tasks, demonstrating an 'assume-malicious' security posture for its internal auditing functions.
- [SAFE]: The instructions and references originate from or point to reputable sources and established projects (e.g., Cisco's AI Defense tools, the
obra/superpowerscommunity skills), focusing on improving reliability and safety through structured review.
Audit Metadata