assess

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes tools such as Bash, Read, Glob, and Grep to investigate project state. The instructions in SKILL.md also suggest the use of a piped command (cat .pi/skills-manifest.json | python3 -c "...") to parse project metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted content from the project codebase (e.g., README files, documentation, and source code).
  • Ingestion points: Accesses project configuration files (pyproject.toml, package.json, etc.), documentation (README.md, CONTEXT.md, docs/), and source code files during the scanning process in assess.py.
  • Boundary markers: The skill does not implement specific technical delimiters or markers to isolate the content of analyzed files from the agent's instructions.
  • Capability inventory: Employs file system tools (Bash, Glob, Read, Grep) and executes a Python-based static analysis script (assess.py). It also references the use of external visualization tools via /create-figure.
  • Sanitization: No evidence of content sanitization or escaping was found for the data read from project files before it is processed by the agent or analysis scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — assess