code-archaeology

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions focus on standard, safe software development practices for code analysis and historical investigation.
  • [COMMAND_EXECUTION]: The skill uses local git commands (git log, git blame, git show, git bisect) to retrieve version control history. These commands are used for their intended purpose of data retrieval and analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for the agent to ingest and analyze external code and commit messages. This is a standard capability for a software development agent and does not introduce unusual risks beyond its primary use case. Ingestion points: Local source files, documentation, and git commit history (SKILL.md). Boundary markers: The skill does not define specific delimiters for untrusted content. Capability inventory: The agent utilizes file reading and local shell execution for git tools. Sanitization: No specific sanitization or filtering of the analyzed code is instructed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — code-archaeology