write-audit
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute project-specific test and validation commands found within the local
AGENTS.mdfile. This is a standard functional requirement for a code auditing tool to verify runtime behavior. - [PROMPT_INJECTION]: The skill inherently possesses an indirect prompt injection surface as it requires the agent to ingest and analyze untrusted content from a local codebase.
- Ingestion points: Local source files, grep search results, and command line outputs are processed by the agent.
- Boundary markers: Absent; the skill relies on the agent's 'Auditor stance' and 'observation-only' instructions rather than technical delimiters to distinguish between code and instructions.
- Capability inventory: The agent has the capability to read files and execute shell commands defined in the local repository.
- Sanitization: Absent; content from files and commands is intended to be recorded directly as evidence.
Audit Metadata