ccx

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the ccx CLI tool to perform code searches, AST greps, and symbol navigation. These commands are executed locally but interact with a remote server via HTTP for data retrieval.
  • [EXTERNAL_DOWNLOADS]: The skill documentation instructs the user to install the cocoindex-code-plus package from PyPI. This is the official tool required for the skill to function and is a standard dependency for this service.
  • [DATA_EXFILTRATION]: While the tool sends queries and code fragments to a remote server, this is the intended primary purpose of the skill (querying a server-side code index). The server URL and API tokens are explicitly managed by the user via environment variables or configuration files, representing standard authorized access rather than exfiltration.
  • [PROMPT_INJECTION]: No malicious prompt injection patterns or instructions to bypass safety guidelines were detected in the instructions.
  • [OBFUSCATION]: No obfuscated URLs, Base64-encoded commands, or hidden characters were found in the provided documentation or reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 06:32 PM
Security Audit — agent-trust-hub — ccx