scope-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill contains purely instructional content for software development tasks, such as identifying public methods, exported APIs, and existing tests. No malicious patterns, obfuscation, or data exfiltration attempts were found.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for the agent to ingest and analyze external data (source code and project metadata), which is a common attack surface for indirect prompt injection.
- Ingestion points: Primary target files and caller/consumer references identified in SKILL.md.
- Boundary markers: None present.
- Capability inventory: The skill itself does not define any executable code or tool calls (e.g., file writing, network access, or shell commands).
- Sanitization: None present.
Audit Metadata