qe-pair-programming

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: Analysis of the skill instructions found no evidence of malicious patterns, prompt injections, or unauthorized data exfiltration. The content is purely instructional and focused on pair programming workflows.
  • [EXTERNAL_DOWNLOADS]: The skill documentation identifies 'claude-flow@alpha' as a prerequisite for installation via the npm registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing external code and feedback during development sessions. Evidence: 1. Ingestion points: User-provided implementation code and feedback in Driver/Navigator modes. 2. Boundary markers: No specific delimiters mentioned in documentation. 3. Capability inventory: Agent-led command execution (git, tests, npm) and file modifications. 4. Sanitization: Use of truth-score verification and automated quality monitoring metrics serves as an integrity gate for processed content.
  • [COMMAND_EXECUTION]: Outlines standard development CLI interactions, such as git operations, test suite execution, and linting, which are necessary for the skill's stated purpose of pair programming.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:15 PM
Security Audit — agent-trust-hub — qe-pair-programming