trends
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
locicommand-line utility to retrieve measurement data. It passes the<project-context>file path and optional function names as shell arguments. - [PROMPT_INJECTION]: Indirect prompt injection risk: The skill processes and renders output from the
lociCLI tool. - Ingestion points: Data returned from
loci trendsexecution. - Boundary markers: Not present; the rendered report incorporates the tool's output directly into the prompt.
- Capability inventory: The skill has the capability to execute shell commands (
loci). - Sanitization: No explicit sanitization of the tool's output is performed before display.
Audit Metadata