skills/agent-sh/agentsys/deslop/Gen Agent Trust Hub

deslop

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes system commands including node and git to perform repository analysis and file diffing. Evidence includes shell blocks executing node ../../scripts/detect.js and git diff.
  • [DYNAMIC_EXECUTION]: The skill dynamically loads and executes logic from internal libraries located at relative paths outside the skill directory. Evidence includes the use of require('../../lib/repo-map') to perform AST-based analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted external codebases which could contain adversarial instructions intended to influence the agent's behavior during code cleanup. Ingestion points: Local files and directories specified by the user or the current environment. Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore instructions embedded in the target code. Capability inventory: The skill has the ability to execute shell commands and load internal modules. Sanitization: No sanitization is performed on the code content before it is processed by detection scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:14 AM
Security Audit — agent-trust-hub — deslop