loopy

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from codebase repositories and thread histories (ingestion points). It addresses this risk with clear boundary markers instructing the agent to treat these sources as reference data only. It maintains a capability inventory limited to bounded, reversible actions and provides explicit sanitization instructions to ignore any embedded overrides or malicious instructions within the analyzed material.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of workflows that may involve shell commands or repository tools. It mitigates potential abuse by restricting execution to ordinary, reversible actions and requiring explicit user approval for destructive changes, production environment modifications, or financial transactions.
  • [DYNAMIC_EXECUTION]: The skill generates and executes agent workflows based on user input and evidence analysis. It employs a validation framework ('Loop Doctor') to ensure generated loops have observable verification checks, bounded authority, and clearly defined terminal states to prevent infinite loops or unauthorized persistence.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves loop catalog data from the vendor-owned domain 'signals.forwardfuture.com'. This communication is restricted to fetching reference documentation in markdown and JSON formats, and the skill provides instructions to verify this data before it is used to influence agent behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:35 PM
Security Audit — agent-trust-hub — loopy