self-feedback-loop

Pass

Audited by Gen Agent Trust Hub on May 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local environment using git commands to check status, diffs, and logs, and to commit code. It also executes test runners identified from the project's own configuration files such as package.json or Makefile.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to read and act upon project files and documentation.
  • Ingestion points: Processes content from AGENTS.md, README.md, docs/plans/, and implementation source code.
  • Boundary markers: None identified; the skill does not wrap ingested content in specific markers to distinguish data from instructions.
  • Capability inventory: Includes file system write permissions for bug fixes and shell command execution for testing and version control.
  • Sanitization: No explicit sanitization or validation of the content of the files read during the review process is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
May 16, 2026, 05:08 PM
Security Audit — agent-trust-hub — self-feedback-loop