audit-reference-originality
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a Python script (
scripts/build_evidence_inventory.py) that invokesgitcommands viasubprocess.check_outputto inspect repository history for deleted or renamed files. These commands are executed within the user-provided site directory and do not involve remote network operations or shell injection vulnerabilities. - [REMOTE_CODE_EXECUTION]: While the skill instructions suggest running a Python script from the skill directory, the code is provided within the skill package and does not fetch or execute arbitrary code from external servers. The static analysis flag for
subprocessin the script is a false positive in this context, as it is used for local Git operations required for the skill's primary auditing purpose. - [DATA_EXPOSURE]: The skill processes project files to identify plagiarism risks but does not exfiltrate this data. Results are written to a local file or standard output as specified by the user.
- [PROMPT_INJECTION]: The skill instructions include boundary enforcement to ensure the AI remains focused on evidence-backed auditing rather than making unsupported legal claims. There are no attempts to bypass safety filters or override system behavior maliciously.
Audit Metadata