simplify

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection (Category 8). It ingests untrusted source code data (Ingestion points: SKILL.md using git and Read tools), lacks explicit boundary markers to separate data from instructions, possesses powerful capabilities (Capability inventory: Edit for file modification and Bash for command execution), and does not apply sanitization to the ingested code content.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run developer commands including git diff, npm run typecheck, npm test, and search tools like ast-grep (sg).
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to execute packages like jscpd and tsc, which may result in downloading dependencies from the npm registry during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 01:41 PM
Security Audit — agent-trust-hub — simplify