contract-strengthening

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill framework includes a strict 'Consent gate' (Step 6) and 'Tool selection' (Step 5) process that explicitly forbids the agent from installing or executing tools without documented resource checks, environment isolation attempts, and explicit user approval. It specifically identifies global installations and privilege escalation (sudo) as high-risk exceptions requiring detailed feasibility assessments.
  • [EXTERNAL_DOWNLOADS]: The skill provides a research reference for various verification backends (e.g., Hypothesis, Z3, Stryker). These references point to official documentation sites and well-known GitHub repositories. The instructions emphasize that these links are for guidance only and do not authorize or imply installation.
  • [PROMPT_INJECTION]: As a review tool, the skill ingests external data such as specifications and code diffs. It mitigates potential injection risks by enforcing a structured 'Open-world risk classification' process, requiring the agent to enumerate risks across multiple axes and maintain 'explicit uncertainty' rather than collapsing results into a default 'safe' state.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:13 AM
Security Audit — agent-trust-hub — contract-strengthening