ce-simplify-code

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard development tools to perform its tasks. It executes git diff and git status to determine the scope of changes, and runs project-specific typecheckers, linters, and test suites in Step 4 to verify that code behavior is preserved after simplification.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection because it ingests and processes untrusted data (source code) which is then used to influence agent actions.
  • Ingestion points: The skill reads the full content of files in the resolved scope and git diffs (Step 1 and Step 2).
  • Boundary markers: The instructions do not specify the use of XML tags, delimiters, or explicit "ignore embedded instructions" warnings when passing the user-controlled code content to the subagent prompts.
  • Capability inventory: The skill has the capability to modify the local filesystem by applying suggested fixes (Step 3) and execute shell commands via the project's test and lint runners (Step 4).
  • Sanitization: There is no evidence of sanitization, escaping, or filtering of the code content before it is interpolated into the prompts for the code-reuse, quality, and efficiency reviewers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:18 PM
Security Audit — agent-trust-hub — ce-simplify-code