acceptance

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a project-local Python script located at .claude/scripts/code_graph to perform code analysis and dependency mapping.
  • [PROMPT_INJECTION]: The instructions utilize highly emphatic and repetitive language (e.g., 'MANDATORY IMPORTANT MUST ATTENTION', 'HARD-GATE') to strictly override agent behavior and enforce specific process constraints such as mandatory task creation and code reading before action.
  • [COMMAND_EXECUTION]: The workflow incorporates standard shell utilities like grep and glob to search the codebase for implementation patterns as part of the verification process.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 09:18 AM
Security Audit — agent-trust-hub — acceptance