loop-builder
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
remotion/package.jsonfile includes dependencies on standard, well-known libraries such asremotion,react, andtypescript. These are used for the optional visualization components of the skill and do not represent a security risk. - [COMMAND_EXECUTION]: The skill provides templates and instructions for automating workflows using common CLI tools including
git,pnpm, andclaude. These operations are intended for managing project state and executing agent loops as described in the documentation. - [DATA_EXFILTRATION]: Templates like
gate-script-example.jsdemonstrate safe practices for handling sensitive information, such as using environment variables (process.env.INTERCOM_TOKEN) for API authentication rather than hardcoding credentials. - [PROMPT_INJECTION]: The skill introduces a framework for 'indirect prompt injection' (Category 8) by designing loops that process external data (e.g., Intercom messages or git diffs). However, it explicitly addresses this risk by instructing the user to define 'Boundaries' and 'Verification' steps that require evidence before the agent can take high-stakes actions.
Audit Metadata