skills/ruvnet/ruflo/agent-refinement/Gen Agent Trust Hub

agent-refinement

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's configuration includes pre and post lifecycle hooks that execute npm test and memory_store commands. These are standard operations for a development-focused skill intended to verify code changes and manage internal state.
  • [DATA_EXPOSURE]: The provided code examples (e.g., Authentication Service, Performance Testing) use mock repositories, local variables, and generic placeholders like user@example.com. There are no hardcoded secrets or patterns indicating sensitive data exposure.
  • [PROMPT_INJECTION]: The instructions are clearly focused on defining the agent's role as a refinement specialist. There are no attempts to bypass safety filters, override system instructions, or extract system prompts.
  • [REMOTE_CODE_EXECUTION]: The skill does not download external scripts or execute code from remote or untrusted sources. All logic and examples are contained within the skill definition.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:37 AM
Security Audit — agent-trust-hub — agent-refinement