scope-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill contains purely instructional content for software development tasks, such as identifying public methods, exported APIs, and existing tests. No malicious patterns, obfuscation, or data exfiltration attempts were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for the agent to ingest and analyze external data (source code and project metadata), which is a common attack surface for indirect prompt injection.
  • Ingestion points: Primary target files and caller/consumer references identified in SKILL.md.
  • Boundary markers: None present.
  • Capability inventory: The skill itself does not define any executable code or tool calls (e.g., file writing, network access, or shell commands).
  • Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 05:26 PM
Security Audit — agent-trust-hub — scope-analysis