humanize-beagle

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several command-line utilities to ensure operational safety and correctness. It uses git status and git stash to protect the user's working directory before making edits. It uses jq to validate the structure of its input data (.beagle/ai-writing-review.json). Finally, it uses python3 (with the ast module) and npx (with acorn) to verify that modifications to source code do not introduce syntax errors.
  • [EXTERNAL_DOWNLOADS]: To validate JavaScript and TypeScript files, the skill runs npx -y acorn. This command fetches the acorn package from the npm registry and executes its CLI tool. As acorn is a well-known, reputable parsing library and npm is an official registry, this download is considered a standard and safe developer workflow.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes AI-generated findings from a JSON file.
  • Ingestion points: Data enters from .beagle/ai-writing-review.json (Step 3).
  • Boundary markers: The skill relies on strict JSON schema validation using jq but does not use explicit prompt delimiters.
  • Capability inventory: The skill can perform git operations, file writes, and syntax parsing via python3 and npx.
  • Sanitization: Edits are performed via string replacement or deletion; non-trivial changes require manual user approval ("Needs Review" fixes), and all edits are followed by syntax validation to ensure no code corruption.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:17 AM
Security Audit — agent-trust-hub — humanize-beagle