loop-builder

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The remotion/package.json file includes dependencies on standard, well-known libraries such as remotion, react, and typescript. These are used for the optional visualization components of the skill and do not represent a security risk.
  • [COMMAND_EXECUTION]: The skill provides templates and instructions for automating workflows using common CLI tools including git, pnpm, and claude. These operations are intended for managing project state and executing agent loops as described in the documentation.
  • [DATA_EXFILTRATION]: Templates like gate-script-example.js demonstrate safe practices for handling sensitive information, such as using environment variables (process.env.INTERCOM_TOKEN) for API authentication rather than hardcoding credentials.
  • [PROMPT_INJECTION]: The skill introduces a framework for 'indirect prompt injection' (Category 8) by designing loops that process external data (e.g., Intercom messages or git diffs). However, it explicitly addresses this risk by instructing the user to define 'Boundaries' and 'Verification' steps that require evidence before the agent can take high-stakes actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM