lsp-index-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill workflow suggests installing several standard language servers and developer tools (e.g., typescript-language-server, intelephense, pyright) via the npm package manager. These are well-known packages from a trusted public registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to index and analyze project source code (e.g., TypeScript, PHP, Python) to build semantic graphs. This activity inherently involves processing untrusted external data, which is necessary for the skill's stated purpose. The agent's capabilities for local indexing and server management are scoped to these tasks. Ingestion points include project source files discovered via globbing and LSP responses; no specific boundary markers or sanitization logic are defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:36 AM
Security Audit — agent-trust-hub — lsp-index-engineer