fp-check
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a highly disciplined and skeptical approach to security analysis, specifically designed to counter common AI biases and pattern-matching errors.- [COMMAND_EXECUTION]: The skill uses the 'Bash' tool to create and run proof-of-concept scripts. This is a functional requirement for its stated purpose of verifying security bugs and is handled through a structured, multi-gate process.- [PROMPT_INJECTION]: The skill includes comprehensive 'Devil's Advocate' and 'Rationalizations to Reject' sections that explicitly instruct the agent to ignore biased thinking and verify all claims against the source code, providing strong resistance to indirect prompt injection from malicious bug reports. Ingestion points: 'SKILL.md' (bug claims) and codebase files via 'Glob/Read'. Boundary markers: restating claims in 'Step 0' and using 'Evidence Templates'. Capability inventory: 'Bash', 'Write', 'Edit', and 'Task' management tools for PoC execution. Sanitization: the multi-gate verification process ('gate-reviews.md') requires empirical evidence before any input is accepted as a true positive.
Audit Metadata