duck-simplify
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were detected. The skill is instructional and focuses on improving code structure through text-based findings.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of code or proposals for review. Ingestion points: Code snippets or architectural proposals provided by the user in the activation phase (SKILL.md). Boundary markers: The skill explicitly references 'references/GUARDRAILS.md' and includes 'Philosophy Guardrails' that instruct the agent to never weaken security controls or trust boundaries during simplification. Capability inventory: There are no capabilities for command execution, file system modification, or network access across any of the skill's files. Sanitization: The skill relies on boundary instructions and the absence of executable capabilities to mitigate injection risks.
Audit Metadata