skills/bnema/opencode-public/hexarch/Gen Agent Trust Hub

hexarch

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a local code analysis tool with no indicators of malicious intent or external network connectivity.\n- [COMMAND_EXECUTION]: The skill utilizes 'git diff' and 'git diff --cached' to establish the scope of its analysis (diff mode versus audit mode), which is a standard and benign development practice.\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection due to its ingestion of repository content.\n
  • Ingestion points: The skill reads project documentation (e.g., CLAUDE.md, AGENTS.md) and repository source code (SKILL.md).\n
  • Boundary markers: No specific delimiters or boundary warnings are used when processing the ingested repository data.\n
  • Capability inventory: The skill can read local files and perform file-write operations when applying 'auto-fixes' for architectural violations.\n
  • Sanitization: No explicit sanitization or filtering of external code content is defined before analysis by the sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 03:23 AM
Security Audit — agent-trust-hub — hexarch