ccf-idea-reviewer
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill integrates explicit privacy-protection protocols, specifically instructing the agent to utilize 'public-safe' keywords when performing external literature searches to prevent the exposure of unpublished user research ideas.
- [COMMAND_EXECUTION]: The skill provides instructions for the execution of a local Python script (
check_sources.py) used for registry maintenance. This script resides within the local workspace ('../ccf-common/scripts/') and does not involve remote code downloads or execution from untrusted sources. - [SAFE]: Input handling is governed by a normalization process that converts unstructured user text into specific 'problem-method cards', which acts as a structured boundary and reduces the risk of the agent misinterpreting data as instructions.
Audit Metadata