agent-coder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill configuration defines standard hooks (
echo,grep, and an optionalnpm run lint) for validating task text locally and linting standard JavaScript files. None of these involve arbitrary code execution or unvetted external scripts. - [SAFE]: The embedded code guidelines explicitly mandate security practices such as avoiding hardcoded secrets, using parameterized queries, and validating inputs.
- [SAFE]: The referenced MCP tools (
mcp__claude-flow__memory_usage,mcp__claude-flow__benchmark_run,mcp__claude-flow__bottleneck_analyze) are used exclusively inside code blocks as examples for memory synchronization and coordination metrics. There are no attempts to bypass user prompts or communicate with unvetted third-party domains.
Audit Metadata