codebase-audit-pre-push

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform broad file system operations, including the immediate deletion of various file types (OS metadata, logs, build artifacts, and dependencies) and the modification of source code to refactor logic or remove dead code.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process entire codebases file-by-line.
  • Ingestion points: All files within the user's project directory (SKILL.md).
  • Boundary markers: None identified; the agent is not explicitly warned to ignore instructions found within the files it audits.
  • Capability inventory: The agent can read files, write/modify code, delete files, and execute shell tools like npm audit.
  • Sanitization: No specific sanitization or filtering of file content is mandated before the agent processes it.
  • [CREDENTIALS_UNSAFE]: The skill directs the agent to scan for sensitive files and hardcoded secrets (e.g., .env, .pem files, API keys). While the stated intent is to secure these credentials by moving them to environment variables, the agent is granted explicit access to sensitive authentication materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 08:28 PM
Security Audit — agent-trust-hub — codebase-audit-pre-push