skills/sprngr/rubber-duck/duck-design/Gen Agent Trust Hub

duck-design

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily instructional and conversational, designed to facilitate design discussions between the AI and a developer through Socratic inquiry.
  • [SAFE]: Includes explicit guardrails in references/GUARDRAILS.md and SKILL.md that mandate the agent refuse any change that would weaken trust-boundary validation, security controls, data-loss prevention, or accessibility requirements.
  • [SAFE]: Implements a 'Duck Ladder' approach to minimize implementation impact, prioritizing existing local helpers, standard libraries, and already-installed dependencies over new code or abstractions.
  • [SAFE]: No obfuscation, data exfiltration patterns, persistence mechanisms, or unauthorized network operations were found in the skill instructions or reference files.
  • [SAFE]: The skill defines a 'Reviewable Unit Decomposition' process to prevent oversized PRs and ensure changes remain reviewable, which is a development best practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 05:20 AM
Security Audit — agent-trust-hub — duck-design