ast-grep
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill suggests using 'nix run nixpkgs#ast-grep' as a fallback installation method. This fetches and executes the tool from the official Nixpkgs repository, which is a well-known and trusted package registry.
- [COMMAND_EXECUTION]: The skill executes local shell commands ('sg' or 'ast-grep') to perform structural searches on source code. It includes explicit guardrails to avoid destructive operations by prohibiting the use of '--rewrite' or '--interactive' flags.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it reads and displays content from the local filesystem that may contain attacker-controlled data.
- Ingestion points: The tool reads source code files from the user's repository during search operations (identified in SKILL.md).
- Boundary markers: The instructions do not specify any boundary markers or delimiters to separate the tool's output from the agent's internal reasoning.
- Capability inventory: The skill possesses the ability to execute shell commands and read files (identified in SKILL.md).
- Sanitization: There is no evidence of sanitization or filtering of the content read from files before it is processed by the agent.
Audit Metadata