analyze
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No malicious override or bypass patterns detected. The skill uses instructional language to enforce a read-only contract and evidence-based reasoning.
- [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file access or network exfiltration patterns found. The skill is explicitly limited to read-only repository analysis.
- [OBFUSCATION]: No hidden content, Base64 encoding, or Unicode tricks detected.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: No external package installations or remote script executions found. References to internal commands like $team are constrained to specific developer runtime environments.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes repository data, its strict read-only mandate and focus on evidence-vs-inference boundaries mitigate the risk of executing embedded instructions.
- [DYNAMIC_CONTEXT_INJECTION]: No dynamic shell commands using the exclamation-backtick syntax were found.
Audit Metadata