duck-patch
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust 'Ask-before-act' philosophy, requiring explicit user approval for any semantic change, including code logic, configuration, and dependency updates. It uses a phased implementation approach (Phase 1: stubs, Phase 2: integration, Phase 3: implementation) with line-count limits and file caps to prevent review fatigue and ensure that changes remain small, bounded, and verifiable. It specifically instructs the agent not to weaken security, trust boundaries, or data-loss prevention. All referenced files and vendor context ('sprngr') are consistent with developer tooling purposes. No malicious patterns such as obfuscation, remote code execution, or data exfiltration were detected.
Audit Metadata