careful

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a protective layer for the developer session. It registers a Bash hook that runs a local Node.js script (careful-guard.mjs) to validate commands before they are executed.
  • [COMMAND_EXECUTION]: The skill defines a hook that executes a Node.js script. This is the intended primary function of the skill to provide a safety guard. The script itself is self-contained and does not perform any network operations or unauthorized file access.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were detected. The guard script reads from stdin (the hook payload) and writes only to stderr and the exit code. It does not use network tools or target sensitive files like credentials.
  • [PROMPT_INJECTION]: The instructions in SKILL.md are focused on explaining the safety boundaries and explicitly instruct the agent not to attempt workarounds for the guard, which aligns with the safety-oriented purpose of the skill.
  • [OBFUSCATION]: The guard script and documentation are written in clear, human-readable text. No obfuscation techniques, hidden characters, or homoglyphs were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 03:45 AM