code-smell-validator

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it processes untrusted project files to generate refactoring plans and guide sub-agent tasks. An attacker could embed instructions within source code comments to manipulate the agent's findings or the subsequent actions taken by refactoring sub-agents.\n
  • Ingestion points: Source code files in the target project are read and analyzed in Phase 2 (Steps 4, 5, 7) and Phase 3 (Step 8).\n
  • Boundary markers: The skill lacks explicit delimiters or instructions for the agent to disregard embedded instructions when processing file content.\n
  • Capability inventory: The skill can execute local shell scripts, write refactoring plan documents to the filesystem, and delegate code-modification tasks to sub-agents.\n
  • Sanitization: There is no evidence of sanitization or filtering of the file content before it is processed by the agent or sub-agents.\n- [COMMAND_EXECUTION]: The skill executes multiple local shell scripts to automate project analysis. These scripts interact directly with the local development environment.\n
  • scripts/detect_stack.sh: Analyzes project manifest files (e.g., package.json, pom.xml) to identify the tech stack.\n
  • scripts/analyze_churn.sh: Runs git log to identify frequently modified files.\n
  • scripts/check_coverage.sh: Checks for the existence of common test coverage report files.\n
  • scripts/check_ts_lint.sh: Invokes npx eslint to detect code complexity and React-specific issues.\n
  • scripts/check_hygiene.sh: Uses grep and npx eslint to identify technical debt such as TODOs or unused imports.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — code-smell-validator