figure-it-out

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a procedural framework for planning and executing complex software changes. It emphasizes rigor, the scientific method, and maintaining an audit trail of decisions.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a general-purpose workflow handler for user-defined tasks. While it ingests task descriptions (untrusted data), it does not include features that automatically process or interpret external content in an unsafe manner. The risk is considered inherent to general AI operation and follows best practices for task decomposition.
  • [COMMAND_EXECUTION]: The instructions mention using 'committed scripts' to produce evidence for audit trails. This refers to scripts already existing within the user's repository/environment rather than downloading or executing unknown code from external sources.
  • [DATA_EXFILTRATION]: There are no patterns suggesting data exfiltration. The 'audit trail' described involves committing a TSV file to the project's repository, which is a standard internal logging practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 12:48 PM
Security Audit — agent-trust-hub — figure-it-out