loop-me
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill is purely instructional and designed for requirements gathering and documentation.
- [COMMAND_EXECUTION]: The skill manages markdown files within a specific path (
workflows/*.mdandNOTES.md) in the local workspace. These are legitimate file operations for its stated purpose of managing workflow specifications. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from
NOTES.md, which could potentially harbor malicious instructions if a user populates it with untrusted content. However, because the skill lacks dangerous capabilities such as network access, system privilege escalation, or arbitrary code execution, this represents a negligible risk surface.
Audit Metadata