code-explanation
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains no malicious code, obfuscation, or persistence mechanisms. Its behavior is consistent with its stated purpose of explaining code and concepts.
- [COMMAND_EXECUTION]: The skill utilizes standard file-system tools (Read, Grep, Glob) and specialized reasoning plugins (Context7, Sequential MCP) to analyze codebases. These operations are performed locally and do not involve the execution of arbitrary shell commands or remote scripts.
- [PROMPT_INJECTION]: The skill ingests target code as data for analysis. While this creates a surface for indirect prompt injection (e.g., instructions hidden in code comments), the skill is functionally scoped to explanation tasks and does not possess high-privilege capabilities that could be abused through such an injection.
- [DATA_EXFILTRATION]: No network-enabled commands or exfiltration patterns were found. The skill operates on the local environment to generate documentation and explanations for the user.
Audit Metadata