semantic-code-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze source code, data flows, and runtime evidence from a working tree. This creates a surface for indirect prompt injection where malicious instructions embedded in the analyzed code could influence the agent's behavior.
  • Ingestion points: Source files, configuration registries, and runtime evidence in the working tree (referenced in SKILL.md).
  • Boundary markers: Absent; there are no specific instructions or delimiters provided to the agent to treat analyzed code as untrusted data or to ignore instructions found within it.
  • Capability inventory: The skill utilizes subprocess execution for running tests and probes, and has read access to the file system.
  • Sanitization: Absent.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to "Use tests and runnable probes to confirm disputed or non-obvious behavior." While intended for verification purposes, this instructs the agent to execute code and commands within the user's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 06:02 PM
Security Audit — agent-trust-hub — semantic-code-analysis