loft
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill provides purely instructional content for a specific software development workflow. It does not include any scripts, commands, or network operations.
- [PROMPT_INJECTION]: No attempts to override agent behavior, bypass safety filters, or extract system prompts were detected. The language is descriptive and focused on workflow methodology.
- [DATA_EXFILTRATION]: The skill does not contain instructions to access sensitive files (such as
.env, SSH keys, or cloud credentials) or perform network requests to external domains. - [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It explicitly instructs the agent to use the repository's existing serve commands and avoid adding new abstractions or build steps.
- [PERSISTENCE]: The skill explicitly forbids persistence, stating that artifacts should have 'no persistence' and 'never dock' with the main branch.
Audit Metadata