ecc-tools-cost-audit
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of purely instructional content for manual auditing and does not include any executable code, shell commands, or external dependencies.- [INDIRECT_PROMPT_INJECTION]: The skill guides the analysis of webhook handlers and queue workers that ingest untrusted GitHub event data. This identifies a potential vulnerability surface in the repository being audited.
- Ingestion points: Webhook routers and queue consumers in the ECC-Tools repository.
- Boundary markers: No explicit delimiters for untrusted input are defined in the workflow.
- Capability inventory: The audited environment includes PR creation, branch management, and premium model invocation.
- Sanitization: The instructions focus on logic flow rather than data sanitization.
Audit Metadata