skills/boshu2/agentops/codebase-recon/Gen Agent Trust Hub

codebase-recon

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a bash script (validate-output.sh) to perform repository state checks and artifact validation.
  • Evidence: Uses standard git, jq, and sha256sum commands to verify the integrity of the repository and generated JSON/Markdown artifacts.
  • Security Control: The script implements a 'snapshot' mechanism using mktemp and cp -P to prevent Time-of-Check Time-of-Use (TOCTOU) attacks where a file might be swapped for a malicious one during the validation process.
  • Security Control: Paths are validated to ensure they are 'safe repository-relative paths,' preventing directory traversal attacks (e.g., rejecting .. or absolute paths).
  • [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or unauthorized persistence were detected. The skill is designed to be read-only regarding the target codebase (it 'does not edit code') and produces documentation artifacts in a restricted directory (.agents/scratch/).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 12:37 PM
Security Audit — agent-trust-hub — codebase-recon