code-quality

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill leverages shell commands such as pnpm, tsc, grep, and find to perform automated linting and code analysis. It also includes a PowerShell script utilizing Get-ChildItem for finding commented-out code blocks.
  • [DYNAMIC_EXECUTION]: The skill executes inline Node.js scripts using node -e to handle complex file analysis tasks, including counting lines in components and validating naming conventions against the file system.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes source code from the project it is reviewing while maintaining permissions to modify the file system and execute shell commands.
  • Ingestion points: Source files (.ts, .tsx) are read from the src/ directory during several steps (Steps 2 through 8) using Grep, Glob, and Read tools.
  • Boundary markers: No explicit markers or instructions are provided to the agent to disregard instructions found within the code being analyzed.
  • Capability inventory: The skill utilizes Shell for running diagnostic tools and Write for applying suggested code improvements.
  • Sanitization: There is no evidence of content sanitization or isolation for the data ingested from the reviewed files.
  • [SAFE]: The skill utilizes @cognite/sdk and references CogniteClient, which are official development resources belonging to the vendor 'cognitedata'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:14 PM