engineering-loop
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a pure instruction set (markdown) providing a methodology for software development. It defines structured workflows for debugging, testing, and reviewing code within a local environment.
- [REMOTE_CODE_EXECUTION]: There are no remote code downloads or execution patterns detected. The skill focuses entirely on 'repository-native validation' and 'local develop-test-review' cycles.
- [DATA_EXFILTRATION]: No network exfiltration patterns or sensitive data access were found. The instructions explicitly warn against querying production, deploying, or publishing without authorization.
- [PROMPT_INJECTION]: The skill contains no instructions intended to bypass safety filters or override the agent's core identity. It uses standard instructional language to guide task performance.
- [PRIVILEGE_ESCALATION]: The skill explicitly includes 'stop conditions' for missing authority or permissions and instructs the agent to stop if an action requires missing secrets or unauthorized destructive actions.
- [OBFUSCATION]: No obfuscated content, Base64 strings, or hidden characters were found in the provided files.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes repository data, it includes robust boundary markers (contract templates, ledgers) and clear instructions to 'resolve routine implementation choices from evidence,' which reduces the surface for accidental obedience to embedded data instructions.
Audit Metadata