debug-rule-reachability
Pass
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill is purely instructional and provides guidance on how to use the
opentaintcommand-line utility for debugging dataflow analysis rules. It does not include any malicious patterns such as prompt injection, obfuscation, or persistence mechanisms. - [COMMAND_EXECUTION]: The skill documents the use of the
opentaint scanandopentaint summarycommands. These commands are used with expected parameters to process local project models and generate analysis reports (SARIF files). No arbitrary or dangerous shell command execution was detected. - [DATA_EXPOSURE_AND_EXFILTRATION]: The skill handles project-related data such as project models and scan results. However, it does not attempt to access sensitive system files (e.g., SSH keys, environment variables) or exfiltrate any data to external servers.
Audit Metadata