code-quality
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill leverages shell commands such as
pnpm,tsc,grep, andfindto perform automated linting and code analysis. It also includes a PowerShell script utilizingGet-ChildItemfor finding commented-out code blocks. - [DYNAMIC_EXECUTION]: The skill executes inline Node.js scripts using
node -eto handle complex file analysis tasks, including counting lines in components and validating naming conventions against the file system. - [INDIRECT_PROMPT_INJECTION]: The skill processes source code from the project it is reviewing while maintaining permissions to modify the file system and execute shell commands.
- Ingestion points: Source files (
.ts,.tsx) are read from thesrc/directory during several steps (Steps 2 through 8) usingGrep,Glob, andReadtools. - Boundary markers: No explicit markers or instructions are provided to the agent to disregard instructions found within the code being analyzed.
- Capability inventory: The skill utilizes
Shellfor running diagnostic tools andWritefor applying suggested code improvements. - Sanitization: There is no evidence of content sanitization or isolation for the data ingested from the reviewed files.
- [SAFE]: The skill utilizes
@cognite/sdkand referencesCogniteClient, which are official development resources belonging to the vendor 'cognitedata'.
Audit Metadata