enforce-standards

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as intended for codebase maintenance and requires explicit user approval of a generated migration plan before executing any changes.
  • [COMMAND_EXECUTION]: The skill uses local shell commands (mv, mkdir) and project-specific tools (npx nx) to restructure files and verify changes (type-checking, linting). These operations are restricted to the local filesystem and the target directory specified by the user.
  • [DATA_EXPOSURE]: The skill reads project documentation and source files to identify naming violations and update import paths. This data access is necessary for its primary function and does not involve any network transmission or external exposure of sensitive information.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content (source code files) to extract export and import patterns for its migration plan. While this presents a potential ingestion surface for malicious instructions embedded in code comments or strings, the risk is mitigated by the requirement for human review of the plan and the specialized nature of the parsing logic.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — enforce-standards