recipe-validate

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill architecture is built around mandatory human oversight, utilizing [STOP — BLOCKING] markers that strictly prevent the agent from executing validation designs or finalizing outcomes without explicit user approval.
  • [SAFE]: Risk-prone activities, such as "Feasibility" code spikes, are performed using isolated worktrees (isolation: "worktree"), ensuring that any code execution for proof-of-concept purposes is contained and automatically cleaned up, preventing persistence or unauthorized modification of the main codebase.
  • [SAFE]: The skill employs context separation when delegating to sub-agents (like the prototype-generator and hypothesis-verifier). This design choice acts as a safeguard against indirect prompt injection from processed data and ensures that validation tests are designed without knowledge of the orchestrator's expectations.
  • [SAFE]: No instances of unauthorized data exfiltration, credential exposure, or obfuscated malicious code were detected. The skill utilizes standard tools like WebSearch and internal codebase analyzers in a manner consistent with its stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:05 AM
Security Audit — agent-trust-hub — recipe-validate