proof-of-work
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill is focused on improving work quality and verification standards.
- [COMMAND_EXECUTION]: The skill provides extensive documentation and examples for using shell commands (e.g.,
ps,ls,curl,jq,pytest,npm) to validate system state and implementation correctness. These are standard diagnostic and testing tools. - [EXTERNAL_DOWNLOADS]: The documentation references standard developer tools and packages from well-known registries (npm, PyPI), including
cclsp,mutmut,ruff, andeslint. These are used for linting, testing, and language server support. - [DATA_EXFILTRATION]: The validation protocols mention commands like
gh auth statusandaws sts get-caller-identityto verify environment readiness. These are used locally for status checks and do not involve sending sensitive data to unauthorized third-party domains. - [PROMPT_INJECTION]: There are no instructions that attempt to bypass safety filters or override agent constraints. The skill instead encourages strict adherence to its own internal validation framework.
Audit Metadata