zero-tech-debt
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading and processing source code from the repository, which constitutes untrusted input. \n- Ingestion points: Uses Read, Grep, and Bash (ripgrep) to analyze files. \n- Boundary markers: None explicitly defined to separate untrusted code from agent instructions. \n- Capability inventory: Can modify files via Edit and execute git commands. \n- Sanitization: The skill relies on structured checklists and human review of commits to mitigate risks. \n- [COMMAND_EXECUTION]: Utilizes git, rg, and fd via Bash for repository auditing and change management. These operations are constrained to standard developer tooling and do not involve arbitrary command execution or unauthorized network access.
Audit Metadata