skills/craftos-dev/craftbot/codeql/Gen Agent Trust Hub

codeql

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes standard build tools such as make, cmake, gradlew, mvn, cargo, and xcodebuild through the codeql database create command to trace the compilation process of the target project.
  • [COMMAND_EXECUTION]: Uses package managers like npm, pip, and go mod to resolve and install dependencies of the project being scanned, ensuring accurate data flow analysis.
  • [EXTERNAL_DOWNLOADS]: Fetches official query packs and community-maintained security packs from GitHub Security Lab and Trail of Bits using the codeql pack download command.
  • [SAFE]: Implements rigorous quality assessment metrics, including baseline lines-of-code verification and extraction error ratios, to ensure the integrity of the CodeQL database before proceeding with analysis.
  • [SAFE]: Utilizes an isolated, auto-incrementing output directory (e.g., static_analysis_codeql_1) for all generated artifacts, protecting the integrity of the host project's source tree.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 05:37 PM
Security Audit — agent-trust-hub — codeql