kernelgen-flagos

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted code from the user's repository to provide context for the code generation process. \n
  • Ingestion points: Reads implementation patterns and test styles from existing files in the repository (e.g., src/flag_gems/ops/). \n
  • Capability: The agent possesses extensive file-write and shell-execution permissions. \n
  • Boundary: The skill contains explicit instructions to confirm destructive actions with the user. \n
  • Sanitization: None detected.\n- [COMMAND_EXECUTION]: The skill makes extensive use of shell commands for environment diagnostics, package installation, and running performance benchmarks. Evidence includes usage of nvidia-smi, conda, pip install, and pytest.\n- [DYNAMIC_EXECUTION]: The skill dynamically generates Python and Triton source files based on MCP tool outputs and subsequently executes these scripts to verify accuracy and measure speedup. This behavior is central to the skill's primary purpose of kernel generation.\n- [DATA_EXFILTRATION]: The skill facilitates the collection of environment metadata and generated code for submission to the vendor via GitHub Issues, Email, or chat tool CLIs. These operations are only performed after explicit user confirmation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:37 PM
Security Audit — agent-trust-hub — kernelgen-flagos