skills/jcosta33/skills/sus-audit/Gen Agent Trust Hub

sus-audit

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run commands to verify dynamic claims during the audit process (Step 4). This is a primary function of the tool and is constrained by instructions to use 'safe checks' and record the output for verification.
  • [DATA_EXPOSURE]: The skill is designed to read and inspect local project files, including source code, tests, and configuration files, to perform its audit. It generates artifacts and sidecars within a specific local directory structure (~/.agents/artifacts/).
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad ingestion surface as it is designed to analyze untrusted source code.
  • Ingestion points: Reads local project source code, callers, tests, and configuration files.
  • Boundary markers: None explicitly defined to ignore embedded instructions in the source code being audited.
  • Capability inventory: Includes command execution (to verify dynamic claims), file writing (artifacts), and file deletion (cleanup during close).
  • Sanitization: Instructions specify 'safe checks' but rely on the agent to distinguish between evidence and executable instructions within the audited files.
  • [SAFE]: No evidence of credential harvesting, unauthorized network exfiltration, or obfuscated content was found. The file deletion capability is part of a user-initiated 'Close' procedure for managing transient audit materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:33 PM
Security Audit — agent-trust-hub — sus-audit