octocode-roast

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions in references/octocode.md direct the agent to install an external dependency using npx octocode skill --name octocode-research. The instructions correctly mandate seeking user consent before performing the installation.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external code (ingestion point: references/roast-playbook.md).
  • Ingestion points: Files and directories specified by the user or identified in a repository diff are read into the context for critique.
  • Boundary markers: The skill employs "Cite or drop it" rules and requires exact file:line anchors, which helps ground the model's output in actual code evidence.
  • Capability inventory: The skill has the ability to modify local files via the references/redemption-flow.md and execute shell commands to install other skills.
  • Sanitization: There are explicit instructions to redact secrets and API keys and to use restrained language for security findings to prevent accidental exposure.
  • [COMMAND_EXECUTION]: The skill includes a local utility script scripts/eval-roast.mjs for performing self-tests and trigger evaluation. Additionally, it uses the octocode CLI for dependency management.
  • [SAFE]: The skill includes a 'Lobby rules' section in SKILL.md that explicitly forbids personal attacks, requires secret redaction, and prevents autonomous code modification (Checkpoints), which are security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 06:16 AM
Security Audit — agent-trust-hub — octocode-roast