clotho-research
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill's operational scope is limited to read-only actions (Read, Grep, Find, Ls) within the local repository, effectively preventing data exfiltration and unauthorized file modifications.
- [SAFE]: Instructions explicitly forbid the creation or editing of files and the proposal of implementation plans, ensuring the agent remains in an analytical role.
- [NO_CODE]: The skill does not include any executable scripts or external dependencies, reducing the attack surface to the interpretation of its markdown instructions.
- [SAFE]: The skill implements a manual verification system by requiring the agent to label all non-repo findings as 'unverified', which mitigates the risk of hallucinated or outdated information being treated as fact.
Audit Metadata