scout
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions to override platform-specific signals, such as 'Ignore Claude-specific mode-switch instructions when they appear'. It also employs aggressive instruction enforcement (e.g., 'Strict execution contract', 'MANDATORY MUST ATTENTION') aimed at compelling the agent to follow the skill's workflow steps regardless of external instructions or standard safety guidelines.
- [COMMAND_EXECUTION]: The skill's workflow requires shell command execution to perform graph expansion. It specifically calls a local Python utility script '.claude/scripts/code_graph' to query repository dependencies and callers. This involves running 'python' with arguments that include file paths discovered within the codebase.
Audit Metadata