coherence-auditor

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Node.js scripts (scripts/coherence-audit.ts) and automated test suites (guides/guides-integrity.test.ts) to perform workspace audits.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is instructed to analyze project documentation and skill definitions.
  • Ingestion points: CONTEXT.md, markdown files within the repository, and skills located in .agents/skills/.
  • Boundary markers: None present in the instructions.
  • Capability inventory: The agent can execute local shell commands through Node.js.
  • Sanitization: The skill contains an explicit 'read-only' directive that prevents the subagent from modifying files based on the content analyzed, mitigating risk of unauthorized changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 05:58 PM
Security Audit — agent-trust-hub — coherence-auditor