dead-code
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes 'npx knip' and a local Node.js script to perform its analysis. These operations are limited to project source code and are standard for development tools.
- [DATA_EXFILTRATION]: Analysis is performed locally on project files. No unauthorized network requests or data transmission to external servers were identified.
- [PROMPT_INJECTION]: The skill processes project source code, which represents a surface for indirect prompt injection. However, the risk is mitigated by explicit instructions for manual verification and a reference guide for false positives. 1. Ingestion points: Project source files. 2. Boundary markers: None explicitly defined. 3. Capability inventory: Bash, Read, Glob, Grep, and local script execution. 4. Sanitization: Reasoning-based verification against false-positives guide.
Audit Metadata