skills/sprngr/rubber-duck/duck-risk/Gen Agent Trust Hub

duck-risk

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override agent constraints. The skill includes a dedicated 'Shared Guardrails' file that explicitly reinforces security controls and user ownership of decisions.
  • [DATA_EXFILTRATION]: No network operations (e.g., curl, fetch) or hardcoded credentials were detected. The skill does not access sensitive local file paths.
  • [REMOTE_CODE_EXECUTION]: The skill consists entirely of Markdown instructions and does not download or execute any external scripts or packages.
  • [OBFUSCATION]: No hidden characters, Base64 encoding, or homoglyphs were found in the text or metadata.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided proposals (untrusted data), it lacks the capabilities (file writes, network sends, or code execution) necessary to facilitate an attack. It functions as a text analyzer only.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 03:17 PM
Security Audit — agent-trust-hub — duck-risk