qe-pair-programming
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: Analysis of the skill instructions found no evidence of malicious patterns, prompt injections, or unauthorized data exfiltration. The content is purely instructional and focused on pair programming workflows.
- [EXTERNAL_DOWNLOADS]: The skill documentation identifies 'claude-flow@alpha' as a prerequisite for installation via the npm registry.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external code and feedback during development sessions. Evidence: 1. Ingestion points: User-provided implementation code and feedback in Driver/Navigator modes. 2. Boundary markers: No specific delimiters mentioned in documentation. 3. Capability inventory: Agent-led command execution (git, tests, npm) and file modifications. 4. Sanitization: Use of truth-score verification and automated quality monitoring metrics serves as an integrity gate for processed content.
- [COMMAND_EXECUTION]: Outlines standard development CLI interactions, such as git operations, test suite execution, and linting, which are necessary for the skill's stated purpose of pair programming.
Audit Metadata