audit-reference-originality

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a Python script (scripts/build_evidence_inventory.py) that invokes git commands via subprocess.check_output to inspect repository history for deleted or renamed files. These commands are executed within the user-provided site directory and do not involve remote network operations or shell injection vulnerabilities.
  • [REMOTE_CODE_EXECUTION]: While the skill instructions suggest running a Python script from the skill directory, the code is provided within the skill package and does not fetch or execute arbitrary code from external servers. The static analysis flag for subprocess in the script is a false positive in this context, as it is used for local Git operations required for the skill's primary auditing purpose.
  • [DATA_EXPOSURE]: The skill processes project files to identify plagiarism risks but does not exfiltrate this data. Results are written to a local file or standard output as specified by the user.
  • [PROMPT_INJECTION]: The skill instructions include boundary enforcement to ensure the AI remains focused on evidence-backed auditing rather than making unsupported legal claims. There are no attempts to bypass safety filters or override system behavior maliciously.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:31 AM
Security Audit — agent-trust-hub — audit-reference-originality