skills/simota/agent-skills/sweep/Gen Agent Trust Hub

sweep

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured cleanup workflow (SCAN → ANALYZE → CATEGORIZE → PROPOSE → EXECUTE → VERIFY) with a strong emphasis on evidence-based decision-making and safety. It explicitly warns against aggressive pruning and prioritizes reversibility.
  • [SAFE]: Comprehensive safety boundaries are established in SKILL.md and reference/exclusion-patterns.md. The skill is forbidden from deleting sensitive files (e.g., .env*, LICENSE*, *.local, lockfiles) and critical paths without extra verification. It also mandates creating a backup branch before any deletions.
  • [SAFE]: The skill relies on established open-source static analysis tools for multiple ecosystems, including knip (JS/TS), vulture (Python), staticcheck (Go), and cargo udeps (Rust). It treats tool output as evidence rather than absolute authority, requiring cross-verification from at least two independent signals.
  • [SAFE]: Instructions include clear guardrails against common cleanup risks, referencing historical incidents like the Knight Capital loss to emphasize the danger of stale feature flags and 'zombie' code.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests and analyzes source code (external data), it mitigates indirect prompt injection risks by requiring static tool confirmation for all LLM findings and maintaining a strict human-in-the-loop verification process before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:48 PM
Security Audit — agent-trust-hub — sweep