analyze

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious override or bypass patterns detected. The skill uses instructional language to enforce a read-only contract and evidence-based reasoning.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file access or network exfiltration patterns found. The skill is explicitly limited to read-only repository analysis.
  • [OBFUSCATION]: No hidden content, Base64 encoding, or Unicode tricks detected.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: No external package installations or remote script executions found. References to internal commands like $team are constrained to specific developer runtime environments.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes repository data, its strict read-only mandate and focus on evidence-vs-inference boundaries mitigate the risk of executing embedded instructions.
  • [DYNAMIC_CONTEXT_INJECTION]: No dynamic shell commands using the exclamation-backtick syntax were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 11:36 AM
Security Audit — agent-trust-hub — analyze