neckbeard

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a comprehensive framework for software engineering delivery. It consists of instructional Markdown files and a Python script (eval/run_eval.py) that uses only the standard library for validating fixture metadata and generating report scaffolds. No suspicious behaviors or malicious intents were identified during the analysis.
  • [COMMAND_EXECUTION]: The skill references the use of terminal commands for its evaluation runner (python3 eval/run_eval.py) and for software verification tasks (e.g., running tests). These commands are standard for software development workflows and do not involve unsafe subprocess spawning or execution of untrusted input.
  • [DATA_EXFILTRATION]: There is no evidence of network operations, credential harvesting, or unauthorized data transmission. The skill instructions prioritize 'Explore' authority by default and explicitly warn against crossing authority boundaries without human confirmation.
  • [PROMPT_INJECTION]: The skill provides structured instructions that reinforce agent safety and discipline, such as requiring evidence for 'Done' verdicts and strictly enforcing authority classes. It does not contain instructions that attempt to bypass safety filters or override system prompts.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. All components are self-contained within the provided repository structure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 10:40 PM
Security Audit — agent-trust-hub — neckbeard