duck-design
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional and conversational, designed to facilitate design discussions between the AI and a developer through Socratic inquiry.
- [SAFE]: Includes explicit guardrails in
references/GUARDRAILS.mdandSKILL.mdthat mandate the agent refuse any change that would weaken trust-boundary validation, security controls, data-loss prevention, or accessibility requirements. - [SAFE]: Implements a 'Duck Ladder' approach to minimize implementation impact, prioritizing existing local helpers, standard libraries, and already-installed dependencies over new code or abstractions.
- [SAFE]: No obfuscation, data exfiltration patterns, persistence mechanisms, or unauthorized network operations were found in the skill instructions or reference files.
- [SAFE]: The skill defines a 'Reviewable Unit Decomposition' process to prevent oversized PRs and ensure changes remain reviewable, which is a development best practice.
Audit Metadata