code-quality-engineer
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill employs local shell commands like cat, jq, and npm, as well as the GitNexus tool, to inspect project files and metadata. These actions are within the expected scope for code quality analysis.
- [COMMAND_EXECUTION]: A dynamic context injection pattern is used in SKILL.md to load shared protocol documentation at runtime. The command is limited to local file system access and serves a legitimate instructional purpose.
- [PROMPT_INJECTION]: By ingesting project-specific configuration and tool outputs, the skill presents a surface for indirect prompt injection. This is documented as a standard risk for agents that process external content, although no active exploit is present.
Audit Metadata