cross-language-check

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local analysis scripts using tools such as Rscript, python (via uv), stata, and julia. This is a core function of the skill to compare quantitative estimates across different language implementations.\n- [COMMAND_EXECUTION]: The skill invokes an internal shared utility script located at <skills-root>/_shared/review-state-log.sh to log the results of replication checks to the project state.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses user-provided source scripts for replication. This represents an attack surface where adversarial content embedded in scripts could potentially influence the agent's behavior during the translation or reporting phases.\n
  • Ingestion points: User-specified source script (Phase 1).\n
  • Boundary markers: None explicitly defined in the instructions for parsing external code.\n
  • Capability inventory: Bash, Write, Edit, Agent.\n
  • Sanitization: No explicit sanitization or filtering of script comments or metadata is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 06:16 AM
Security Audit — agent-trust-hub — cross-language-check