ifcos-agents-code-validator

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to provide an educational and logic-based framework for static code analysis. All provided code snippets are benign examples of library usage and best practices for the IfcOpenShell Python library.
  • [EXTERNAL_DOWNLOADS]: Includes links to the official IfcOpenShell documentation (docs.ifcopenshell.org) and BuildingSmart technical standards (technical.buildingsmart.org). These are trusted domains belonging to the developers of the technology being audited and represent safe, well-known resources.
  • [PROMPT_INJECTION]: As a code validator, the skill is designed to ingest and analyze untrusted user-provided Python scripts. This creates a surface for indirect prompt injection (Category 8). However, the skill acts solely as a reviewer and does not include instructions to execute the code or perform network operations based on its content, making the risk profile minimal and appropriate for its purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:17 PM
Security Audit — agent-trust-hub — ifcos-agents-code-validator