tech-debt

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is configured with a restricted toolset (Read, Glob, Grep, and Write) that limits its operations to the local filesystem. This configuration prevents unauthorized network communication and external data exfiltration.
  • [SAFE]: All identified operations align with the skill's stated purpose of tracking technical debt. The processes for scanning, adding, prioritizing, and reporting do not involve suspicious command execution, privilege escalation, or persistence mechanisms.
  • [SAFE]: Although the skill processes content from the codebase, its actions are strictly limited to pattern matching and categorization. It does not interpret or execute instructions found within comments or code files, which mitigates the risk of indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — tech-debt