codeql
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill automates the installation of dependencies for the project being analyzed (e.g., via pip, npm, or Maven) and system-level utilities (e.g., LLVM, Rosetta) necessary for CodeQL build tracing. These operations are transparent, documented, and essential for the tool's core functionality.
- [COMMAND_EXECUTION]: Uses the CodeQL CLI and standard build tools (make, cmake, gradle, etc.) to generate and analyze databases. It includes specific mitigations for complex environments like macOS Apple Silicon.
- [EXTERNAL_DOWNLOADS]: Integrates with official GitHub and Trail of Bits query packs, which are trusted industry-standard resources for security analysis.
- [COMMAND_EXECUTION]: Manages the deployment of custom data extensions to enhance scanning accuracy, involving file operations within the CodeQL tool's local configuration directories.
Audit Metadata