normalize

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script executes a Python script using the uv tool. This is standard behavior for managing Python environments and running the skill's logic.
  • [DATA_EXFILTRATION]: The skill has the capability to read from and write to the local file system using the normalize.py script. This is the primary intended function of the tool (processing text files). No unauthorized network activity or data exfiltration patterns were detected.
  • [PROMPT_INJECTION]: The skill processes untrusted input text, creating a surface for indirect prompt injection. 1. Ingestion points: normalize.py reads data from files or standard input using Path.read_text() and sys.stdin.buffer.read(). 2. Boundary markers: None. The script processes the entire input as a single block of text. 3. Capability inventory: The skill can read and write files on the local system (normalize.py). 4. Sanitization: The tool is itself a sanitizer that removes Unicode obfuscation (zero-width characters, homoglyphs), which typically enhances security against certain injection techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — normalize