code-assistant

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes repository files to maintain code consistency, which presents a surface for indirect prompt injection if repository files contain adversarial instructions designed to influence the agent's behavior.
  • Ingestion points: The skill reads existing repository files in the current project to match code patterns.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded instructions when reading project files.
  • Capability inventory: The skill is capable of generating file diffs and suggesting shell commands (building, linting, installing packages) via the suggest-shell tool.
  • Sanitization: No specific sanitization or validation of the ingested file content is mentioned.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to suggest shell commands for environment setup, package management, and build processes (e.g., pnpm create next-app, pnpm build, npm install @skillcodex/skills).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 03:03 AM
Security Audit — agent-trust-hub — code-assistant