ln-54-codebase-auditor

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data (source code, manifests, and documentation) from the repository being audited, which is a vector for indirect prompt injection.
  • Ingestion points: The skill accesses repository content using native file listing, manifests, build files, and language servers as specified in the 'Tool Routing' section.
  • Boundary markers: The instructions include a checklist to distinguish confirmed reachability and context from static suspicion, though they do not provide specific text-based delimiters for content interpolation.
  • Capability inventory: The skill is authorized to run repository-defined build, lint, type, test, and smoke commands, as well as git operations and package audits.
  • Sanitization: The instructions explicitly mandate the redaction of raw credential values and sensitive data in the audit report.
  • [DYNAMIC_EXECUTION]: The skill executes repository-defined diagnostic commands (e.g., build scripts, test suites, and smoke tests) to verify delivery health. This constitutes execution of code found within the audited environment.
  • [COMMAND_EXECUTION]: The agent is instructed to use various CLI tools including git, language servers, and package managers to perform its analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 07:49 AM
Security Audit — agent-trust-hub — ln-54-codebase-auditor