tools-ast-grep

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for structural code analysis using the ast-grep utility. It provides specific patterns for identifying architectural issues such as forbidden imports, direct database access, and framework leaks. Analysis of the instructions shows no evidence of malicious intent or dangerous operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with repository source code, representing a data ingestion surface. However, the use of a syntax-tree matcher to produce line-anchored hits is a low-risk operation, as the tool does not execute the code or interpolate large amounts of untrusted content into the agent's response, and the skill lacks network or file-writing capabilities that could be exploited via injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 10:31 AM
Security Audit — agent-trust-hub — tools-ast-grep