extend-before-create
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
opensrcutility to fetch source code from well-known package registries (NPM, PyPI) and GitHub repositories (e.g.,npx opensrc fetch zod) for the purpose of code inspection and reuse analysis. - [COMMAND_EXECUTION]: The skill's instructions involve the use of
bashfor repository searches (grep,find,ls) andnpxfor executing theopensrcinspection tool. - [REMOTE_CODE_EXECUTION]: The skill contains patterns for retrieving and potentially executing logic from remote packages via
npx opensrc, which downloads source code to a global cache for agent consumption. - [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection as it requires the agent to read and analyze content from the local codebase and external dependencies, which could contain adversarial instructions.
- Ingestion points: Repository files accessed via
grepandfind; external source code fetched viaopensrc(SKILL.md). - Boundary markers: Absent; the skill does not define specific delimiters for separating analyzed code from its own instructions.
- Capability inventory: The skill has access to the
Bashtool, enabling arbitrary command execution. - Sanitization: No sanitization or validation of the ingested code content is specified before analysis.
Audit Metadata