ast-grep
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
install.shandinstall.ps1scripts download theast-grepbinary from its official GitHub repository releases. - [COMMAND_EXECUTION]: The
scripts/ast_grep_helper.pywrapper usessubprocess.runto execute thesg(ast-grep) binary and system package managers likebrew,npm, andcargoto manage the installation. - [REMOTE_CODE_EXECUTION]: The skill downloads and executes a remote binary as its core mechanism for performing structural code analysis. This behavior is consistent with the skill's documented purpose.
- [PROMPT_INJECTION]: The skill processes source code files which may contain embedded instructions designed to influence the agent's structural matching and rewriting operations.
- Ingestion points: Local filesystem paths provided as arguments to the
search,replace, andscansubcommands. - Boundary markers: The skill instructions emphasize running dry-run previews before applying modifications, acting as a manual verification step.
- Capability inventory: Structural code search, file read/write access, and execution of the
ast-greputility. - Sanitization: The Python helper includes a pattern validation layer that identifies regex syntax and language-specific errors before the binary is invoked.
Audit Metadata