humanize-beagle
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several command-line utilities to ensure operational safety and correctness. It uses
git statusandgit stashto protect the user's working directory before making edits. It usesjqto validate the structure of its input data (.beagle/ai-writing-review.json). Finally, it usespython3(with theastmodule) andnpx(withacorn) to verify that modifications to source code do not introduce syntax errors. - [EXTERNAL_DOWNLOADS]: To validate JavaScript and TypeScript files, the skill runs
npx -y acorn. This command fetches theacornpackage from the npm registry and executes its CLI tool. Asacornis a well-known, reputable parsing library and npm is an official registry, this download is considered a standard and safe developer workflow. - [INDIRECT_PROMPT_INJECTION]: The skill processes AI-generated findings from a JSON file.
- Ingestion points: Data enters from
.beagle/ai-writing-review.json(Step 3). - Boundary markers: The skill relies on strict JSON schema validation using
jqbut does not use explicit prompt delimiters. - Capability inventory: The skill can perform
gitoperations, file writes, and syntax parsing viapython3andnpx. - Sanitization: Edits are performed via string replacement or deletion; non-trivial changes require manual user approval ("Needs Review" fixes), and all edits are followed by syntax validation to ensure no code corruption.
Audit Metadata