debug-rule-reachability

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill is purely instructional and provides guidance on how to use the opentaint command-line utility for debugging dataflow analysis rules. It does not include any malicious patterns such as prompt injection, obfuscation, or persistence mechanisms.
  • [COMMAND_EXECUTION]: The skill documents the use of the opentaint scan and opentaint summary commands. These commands are used with expected parameters to process local project models and generate analysis reports (SARIF files). No arbitrary or dangerous shell command execution was detected.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles project-related data such as project models and scan results. However, it does not attempt to access sensitive system files (e.g., SSH keys, environment variables) or exfiltrate any data to external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 10:24 AM
Security Audit — agent-trust-hub — debug-rule-reachability