flag-dont-flip

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is focused on process management and documentation. It defines a structured methodology for agents to interact with RFCs and ADRs without introducing automated or hidden behaviors.
  • [SAFE]: No network operations, credential usage, or sensitive file system access outside of project-specific RFC directories were detected. The skill uses standard markdown files for logging and planning.
  • [SAFE]: The workflow incorporates a human-in-the-loop 'Gate' step (Step 3) where the agent must stop for approval before writing code. This serves as a significant security control against both direct and indirect prompt injection attempts that might be present in design documents.
  • [SAFE]: The skill does not perform any dynamic code execution, remote downloads, or package installations. It relies on referenced external skills for specific tasks (like authorship or auditing) but its own instructions are strictly procedural.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:35 AM
Security Audit — agent-trust-hub — flag-dont-flip