leverage-finder

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not contain any suspicious code, remote downloads, or unauthorized network operations. Its instructions are exclusively focused on the analytical task of mapping system elements to leverage points.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it ingests untrusted data from user-provided files or text descriptions using the Read tool (Phase 1). It lacks specific boundary markers or sanitization instructions for this input. However, the risk is negligible because the skill's execution environment is restricted to the Read and AskUserQuestion tools, and it has no capability to execute code or perform network requests.
  • [COMMAND_EXECUTION]: The README.md file contains shell commands for local installation (mkdir, cp). These are standard, transparent commands used for setting up Claude Code skills and do not pose a security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 02:04 PM
Security Audit — agent-trust-hub — leverage-finder