ast-grep

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The install.sh and install.ps1 scripts download the ast-grep binary from its official GitHub repository releases.
  • [COMMAND_EXECUTION]: The scripts/ast_grep_helper.py wrapper uses subprocess.run to execute the sg (ast-grep) binary and system package managers like brew, npm, and cargo to manage the installation.
  • [REMOTE_CODE_EXECUTION]: The skill downloads and executes a remote binary as its core mechanism for performing structural code analysis. This behavior is consistent with the skill's documented purpose.
  • [PROMPT_INJECTION]: The skill processes source code files which may contain embedded instructions designed to influence the agent's structural matching and rewriting operations.
  • Ingestion points: Local filesystem paths provided as arguments to the search, replace, and scan subcommands.
  • Boundary markers: The skill instructions emphasize running dry-run previews before applying modifications, acting as a manual verification step.
  • Capability inventory: Structural code search, file read/write access, and execution of the ast-grep utility.
  • Sanitization: The Python helper includes a pattern validation layer that identifies regex syntax and language-specific errors before the binary is invoked.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 01:59 AM