assess
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes tools such as
Bash,Read,Glob, andGrepto investigate project state. The instructions inSKILL.mdalso suggest the use of a piped command (cat .pi/skills-manifest.json | python3 -c "...") to parse project metadata. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted content from the project codebase (e.g., README files, documentation, and source code).
- Ingestion points: Accesses project configuration files (
pyproject.toml,package.json, etc.), documentation (README.md,CONTEXT.md,docs/), and source code files during the scanning process inassess.py. - Boundary markers: The skill does not implement specific technical delimiters or markers to isolate the content of analyzed files from the agent's instructions.
- Capability inventory: Employs file system tools (
Bash,Glob,Read,Grep) and executes a Python-based static analysis script (assess.py). It also references the use of external visualization tools via/create-figure. - Sanitization: No evidence of content sanitization or escaping was found for the data read from project files before it is processed by the agent or analysis scripts.
Audit Metadata