codebase-recon
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bash script (
validate-output.sh) to perform repository state checks and artifact validation. - Evidence: Uses standard
git,jq, andsha256sumcommands to verify the integrity of the repository and generated JSON/Markdown artifacts. - Security Control: The script implements a 'snapshot' mechanism using
mktempandcp -Pto prevent Time-of-Check Time-of-Use (TOCTOU) attacks where a file might be swapped for a malicious one during the validation process. - Security Control: Paths are validated to ensure they are 'safe repository-relative paths,' preventing directory traversal attacks (e.g., rejecting
..or absolute paths). - [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or unauthorized persistence were detected. The skill is designed to be read-only regarding the target codebase (it 'does not edit code') and produces documentation artifacts in a restricted directory (
.agents/scratch/).
Audit Metadata