skills/lassejlv/skills/clean-codebase/Gen Agent Trust Hub

clean-codebase

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and process the entire repository, including comments, implementations, and documentation. This creates a surface for indirect prompt injection where malicious instructions embedded in the codebase could attempt to influence the agent's cleanup recommendations or implementation steps.
  • [COMMAND_EXECUTION]: The workflow requires running repository-provided validation scripts, tests, and third-party audit tools (like Knip or Madge) to establish baselines and verify changes. This involves executing code and commands defined within the target workspace.
  • [EXTERNAL_DOWNLOADS]: The instructions mention using external tools such as Knip and Madge for code analysis. However, the skill explicitly advises against adding permanent dependencies and suggests using ephemeral invocations only if permitted by the user environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 04:06 PM
Security Audit — agent-trust-hub — clean-codebase