dead-code

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes 'npx knip' and a local Node.js script to perform its analysis. These operations are limited to project source code and are standard for development tools.
  • [DATA_EXFILTRATION]: Analysis is performed locally on project files. No unauthorized network requests or data transmission to external servers were identified.
  • [PROMPT_INJECTION]: The skill processes project source code, which represents a surface for indirect prompt injection. However, the risk is mitigated by explicit instructions for manual verification and a reference guide for false positives. 1. Ingestion points: Project source files. 2. Boundary markers: None explicitly defined. 3. Capability inventory: Bash, Read, Glob, Grep, and local script execution. 4. Sanitization: Reasoning-based verification against false-positives guide.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 04:27 AM
Security Audit — agent-trust-hub — dead-code