loft

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill provides purely instructional content for a specific software development workflow. It does not include any scripts, commands, or network operations.
  • [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The language is descriptive and focused on workflow methodology.
  • [DATA_EXFILTRATION]: The skill does not contain instructions to access sensitive files (such as .env, SSH keys, or cloud credentials) or perform network requests to external domains.
  • [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It explicitly instructs the agent to use the repository's existing serve commands and avoid adding new abstractions or build steps.
  • [PERSISTENCE]: The skill explicitly forbids persistence, stating that artifacts should have 'no persistence' and 'never dock' with the main branch.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 02:47 AM
Security Audit — agent-trust-hub — loft