skills/bigdra50/skills/review-metrics/Gen Agent Trust Hub

review-metrics

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill implements standard code auditing workflows using local static analysis tools. No remote network calls or unauthorized data access patterns were found.\n- [COMMAND_EXECUTION]: Legitimate use of shell commands (unilyze, jb inspectcode, jq) to generate and parse analysis snapshots. The execution is scoped to the local project environment.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code and tool outputs. This is a low-severity surface inherent to code analysis.\n
  • Ingestion points: Reads local C# source files and SARIF reports.\n
  • Boundary markers: Absent for source code read.\n
  • Capability inventory: Shell execution (unilyze, jb, jq), file system read/write.\n
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 01:15 PM
Security Audit — agent-trust-hub — review-metrics