skills/klh/speedy-claude/ast-grep/Gen Agent Trust Hub

ast-grep

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The content is entirely focused on providing documentation and workflows for the ast-grep structural search tool. No malicious code, obfuscation, or unauthorized access patterns were found.
  • [DYNAMIC_EXECUTION]: The skill's workflow includes generating temporary test files and executing the ast-grep CLI tool to validate patterns, which is standard for code analysis tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user input to generate ast-grep patterns. It addresses potential injection risks by instructing the agent to escape metavariables (\$VAR) when using the CLI. Evidence: 1. Ingestion points: User queries for code patterns in SKILL.md; 2. Boundary markers: YAML rule structure and CLI argument separation; 3. Capability inventory: ast-grep CLI execution for file reading; 4. Sanitization: Mandatory shell variable escaping instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — ast-grep