code-quality

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform static analysis and security auditing using standard Elixir tools including mix credo, mix sobelow, mix deps.audit, and mix hex.audit.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external Elixir source code and HEEx templates, which creates a potential surface for indirect prompt injection.
  • Ingestion points: Elixir source files and templates (SKILL.md, assets/refactoring_checklist.md).
  • Boundary markers: None explicitly defined.
  • Capability inventory: Execution of mix analysis tools.
  • Sanitization: Relies on external static analysis tool parsing.
  • [SAFE]: No signs of malicious behavior, credential theft, or unauthorized persistence were found. The skill follows standard engineering practices (Functional Core, Imperative Shell) and uses reputable community-maintained tools for its analysis tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 11:12 PM
Security Audit — agent-trust-hub — code-quality