code-execution-skill

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured software development lifecycle (SDLC) that integrates security verification and review as mandatory steps before completing a code change.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the Bash tool for building artifacts and running test suites. This behavior is standard for development tasks and is governed by a planned implementation scope.
  • [PROMPT_INJECTION]: The skill is designed to process external inputs such as change requests and repository context, which represents a potential vector for indirect prompt injection. However, the workflow explicitly mitigates this risk by requiring security review and verification stages to analyze and sanitize the implemented logic.
  • [DATA_EXFILTRATION]: Tools with network access capabilities (WebFetch, Browser) are utilized during the verification stage to inspect runtime behavior. This usage is consistent with the skill's stated purpose of monitoring behavior, console output, and network requests for quality assurance.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 06:16 PM
Security Audit — agent-trust-hub — code-execution-skill