ln-33-code-modernizer

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with external data by reading repository source code, package manifests, and official documentation. While this creates a surface for indirect prompt injection, the risk is mitigated by the skill's mandatory verification workflows and emphasis on official sources. In accordance with the analyzer instructions, the severity is dropped for this specific use case as the behavior is necessary for the skill's primary modernization purpose.
  • Ingestion points: Repository source files, lockfiles, and official package registry documentation (SKILL.md).
  • Boundary markers: The instructions do not specify explicit delimiters for untrusted data like package documentation.
  • Capability inventory: Executes native package manager commands and performs file system writes (SKILL.md).
  • Sanitization: Relies on regression testing, differential analysis, and user authorization for critical operations.
  • [SAFE]: The overall logic of the skill promotes security best practices, such as verifying dependency licenses, checking security advisories, and requiring explicit user authorization for changes in non-disposable environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 05:02 AM
Security Audit — agent-trust-hub — ln-33-code-modernizer