project-linting
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run 'linting-commands' and 'linting-scripts' that are defined within the project being analyzed. This behavior grants the repository control over the shell commands executed by the agent, potentially allowing arbitrary code execution if the repository contains malicious configuration files.
- [INDIRECT_PROMPT_INJECTION]: \n- Ingestion points: Local repository files including configuration files (e.g., package.json, Makefile) and shell scripts.\n- Boundary markers: Absent; there are no instructions to verify or delimit the commands before they are run.\n- Capability inventory: The agent has the ability to execute shell commands and run local scripts.\n- Sanitization: None; the skill lacks any validation or human-in-the-loop requirement before executing project-defined scripts.
Audit Metadata