sift-codebase-audit
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust 'Non-negotiable operating contract' that strictly enforces read-only behavior, forbidding any edits to the repository, execution of tests, or network operations.
- [COMMAND_EXECUTION]: The skill uses standard local inspection tools such as git, cat, and grep to analyze the codebase, which is consistent with its intended purpose and restricted to read-only operations.
- [EXTERNAL_DOWNLOADS]: Installation instructions utilize npx and git clone to fetch the skill from the vendor's official GitHub repository (2389-research/sift), representing standard installation procedures from a known source.
Audit Metadata