skills/sprngr/rubber-duck/duck-debug/Gen Agent Trust Hub

duck-debug

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious instructions, obfuscation, or exfiltration patterns were detected. The skill's primary function is logical analysis through the Socratic method.
  • [SAFE]: The skill implements a robust 'Mutating Action Gate' that explicitly prohibits edits, mutating commands, or task delegation without prior user approval on a bounded scope.
  • [SAFE]: Regarding potential indirect prompt injection: The skill processes untrusted user data (code, logs) and has the capability to suggest workspace modifications. This attack surface is effectively mitigated by mandatory 'ask-before-act' policies and human-in-the-loop approval requirements for all mutating actions as defined in references/GUARDRAILS.md and the Mutating Action Gate section of SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 09:03 PM
Security Audit — agent-trust-hub — duck-debug