clean-code-guard

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides structured instructions for the agent to adopt a code-review persona. It does not attempt to bypass safety filters or override core system instructions in a malicious way; rather, it establishes a framework for quality assurance and error detection in generated code.
  • [DATA_EXFILTRATION]: No sensitive data exposure or exfiltration patterns were identified. The skill is entirely instructional and does not utilize any network tools, shell commands, or access sensitive file paths like credentials or configuration files.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or external downloads were detected. The reference to external sources is purely for documentation and bibliography purposes, citing legitimate academic research and established engineering blogs.
  • [EXTERNAL_DOWNLOADS]: The skill identifies itself as a portable instruction skill requiring no network access or local executables. All references to external papers and articles in references/sources.md point to well-known academic (arXiv, USENIX) and industry (Martin Fowler, Uncle Bob) domains.
  • [COMMAND_EXECUTION]: There are no scripts, shell commands, or dynamic context injections (!command) present in the skill files. It relies solely on the agent's internal reasoning to apply the provided principles.
  • [OBFUSCATION]: No obfuscated content, Base64 strings, zero-width characters, or homoglyph substitutions were found in any of the skill files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 11:46 AM
Security Audit — agent-trust-hub — clean-code-guard