constant-time-analysis
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes system compilers and disassemblers (e.g.,
gcc,clang,rustc,node,php, anddotnet) using thesubprocessmodule to perform its analysis. These calls are implemented securely using argument lists and do not utilize a shell, which effectively mitigates command injection risks. - [SAFE]: The skill is a legitimate security tool for analyzing cryptographic implementations for constant-time properties. It is well-documented and targets known vulnerability patterns like the KyberSlash attack.
- [SAFE]: No malicious behaviors such as prompt injection, data exfiltration, or obfuscation were identified. Documentation and external links point to reputable security research and official language repositories.
Audit Metadata