backend-ops
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes 'grep' to audit local source files for logging and tracing implementations and 'curl' to query health and metrics endpoints on 'localhost'. These commands are standard for project auditing and diagnostic workflows.
- [PROMPT_INJECTION]: The skill ingests data from local project memory files and source code to inform its recommendations. This ingestion point (files in '.opencode/everything-backend-memory/') lacks explicit boundary markers or sanitization, creating an indirect prompt injection surface. However, the skill's capabilities are restricted to code generation and local diagnostics.
- [EXTERNAL_DOWNLOADS]: The skill references established and reputable third-party libraries including 'pino', 'prom-client', 'structlog', and 'prometheus-fastapi-instrumentator' within its code generation templates.
Audit Metadata