tools-lsp-tree-sitter

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill defines procedures for using local analysis tools (LSP and tree-sitter) without involving remote network access, credential harvesting, or unauthorized data access.
  • [COMMAND_EXECUTION]: Instructs the agent to use the standard tree-sitter CLI for parsing code and running syntax queries. The command usage is correctly scoped to local source files and aligns with the skill's intended purpose for code analysis.
  • [PROMPT_INJECTION]: While the skill processes project source code (an indirect prompt injection surface), it does not contain instructions that attempt to bypass safety filters or override agent constraints. The risk is inherent to code analysis tasks and is not an intentional malicious feature of this skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:19 AM
Security Audit — agent-trust-hub — tools-lsp-tree-sitter