incremental-implementation

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill and its reference files exclusively contain documentation, workflow instructions, and security best practices. All external tools mentioned (e.g., npm, pytest, lighthouse) are industry-standard development utilities used for verification.- [INDIRECT_PROMPT_INJECTION]: The skill processes external task specifications and plans. It provides strong mitigation strategies through 'Rule 0.5: Scope Discipline' and mandatory verification cycles to ensure the agent only performs intended actions. The documentation provides clear boundaries for agent behavior.- [DATA_EXPOSURE]: While the security checklist mentions sensitive file paths (e.g., .env, .pem, .ssh), it does so to instruct users and agents on how to properly exclude and protect them using .gitignore and other security measures. No commands are present to exfiltrate this data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:54 AM
Security Audit — agent-trust-hub — incremental-implementation