analysis-core

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests installing missing dependencies from the author's GitHub repository using the command 'npx skills add FuDesign2008/open-skills'. As this is a vendor-owned resource, it is documented neutrally.
  • [COMMAND_EXECUTION]: The methodology involves using 'bash' for read-only verification commands and 'npx' for dependency management.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external source code, creating an attack surface for indirect prompt injection. Ingestion points: Local source code files analyzed via Read, Grep, and SemanticSearch tools (SKILL.md). Boundary markers: Absent. Capability inventory: bash, Edit/Write, and WebSearch. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 10:21 AM
Security Audit — agent-trust-hub — analysis-core