octocode-research

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources such as GitHub and NPM using tools like ghGetFileContent, ghCloneRepo, and npmSearch. While specific sanitization is not explicitly implemented, the skill provides strong boundary markers via the 'Proof Ladder' and 'Researcher Mindset' instructions, which require the agent to cross-verify all findings and treat search results as leads rather than proof. The capability inventory includes file system access and platform-provided network tools, but the risk is mitigated by mandatory instructions to ask for user permission before executing any code from these sources.
  • [COMMAND_EXECUTION]: Local maintenance scripts (scripts/check-description.mjs and scripts/eval-research.mjs) are used to validate skill metadata and evaluate performance. These scripts utilize Node.js built-in modules for file I/O and pattern matching; they do not incorporate subprocess execution or unsafe evaluation of untrusted input.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 06:53 PM
Security Audit — agent-trust-hub — octocode-research