duck-debt
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is strictly read-only and focuses on the identification and classification of code comments (TODO, FIXME, HACK, XXX) into a structured report.
- [SAFE]: It adheres to a shared guardrail policy in references/GUARDRAILS.md that explicitly forbids weakening security controls, trust-boundary validations, or data-loss prevention measures.
- [SAFE]: No network operations, credential harvesting, or remote code execution patterns were identified in the instruction set.
- [SAFE]: Indirect prompt injection risks are effectively mitigated by a rigid output contract and a narrow read-only scope that prevents external data from influencing agent behavior beyond reporting.
Audit Metadata