jiaojie

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in internal utility scripts (scripts/project_check.py and tools/capture_project_evidence.py). These scripts are intended for development-time unit testing and corpus generation, rather than during the agent's primary task-execution runtime.\n- [DYNAMIC_EXECUTION]: The code in scripts/_vendor/lch/util.py uses ctypes.CDLL to access standard C library functions (renameatx_np on macOS or renameat2 on Linux) to perform atomic file renames. This is a secure programming practice for ensuring file integrity and is not a malicious dynamic loading pattern.\n- [OBFUSCATION]: A test fixture file (assets/vectors/language-unicode-v1-001.json) contains bidirectional (Bidi) Unicode control characters. These characters are explicitly identified in the file as test vectors for the skill's built-in Bidi detection logic and do not represent an attempt to hide instructions.\n- [DATA_EXFILTRATION]: The skill processes task contexts but contains no networking code or external domain references for data transfer. It strictly manages local files and archive creation.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it is designed to process context from previous AI sessions, but it manages this risk through robust safeguards.\n
  • Ingestion points: scripts/handoff.py reads user-supplied context from handoff.md, handoff.zip, and handoff-audit.zip.\n
  • Boundary markers: SKILL.md and references/security-boundary.md contain explicit instructions for the AI to treat incoming data as untrusted and to ignore any embedded instructions.\n
  • Capability inventory: The skill performs local file operations (read/write/hash/zip) using standard Python libraries and includes no network access.\n
  • Sanitization: scripts/_vendor/lch/security.py implements a static scanner that checks for hardcoded credentials, absolute system paths, active content (HTML, JS, shell shebangs), and Unicode control characters before processing data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:03 AM
Security Audit — agent-trust-hub — jiaojie