global-coding-style

Warn

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [DATA_EXFILTRATION]: The skill contains a relative path traversal link that attempts to access documentation located outside the skill's root directory. Path traversal sequences can be exploited to read sensitive system or configuration files beyond the intended scope. Evidence: [global coding style](../../../agent-os/standards/global/coding-style.md) in SKILL.md at line 30.
  • [INDIRECT_PROMPT_INJECTION]: The skill's skill-report.json file contains self-referential safety claims designed to override automated security analysis. 1. Ingestion points: skill-report.json metadata fields. 2. Boundary markers: Absent. 3. Capability inventory: The skill is intended for code formatting and analysis, requiring file system access and execution of tools like Laravel Pint and Larastan. 4. Sanitization: Absent.
  • [METADATA_POISONING]: The skill-report.json file contains contradictory and deceptive metadata. It identifies high-severity risks while simultaneously declaring a 'safe' verdict, which can mislead users about the actual security posture of the skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 8, 2026, 08:59 PM
Security Audit — agent-trust-hub — global-coding-style