deep-code-intelligence

Pass

Audited by Gen Agent Trust Hub on Apr 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust reasoning framework for high-stakes software engineering tasks, focusing on evidence collection and hypothesis validation before code changes occur. All described workflows align with best practices for principal engineering and architecture analysis.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool and provides template examples for standard development tasks such as running tests (pnpm test), type checking (npx tsc), and deployment verification. These operations are within the expected scope of a deep code intelligence tool and are used for validating implementation safety rather than performing malicious actions.
  • [DATA_EXFILTRATION]: No unauthorized network operations, data extraction patterns, or access to sensitive credential files were identified. The workflow focuses on local repository analysis and standard validation pipelines.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests repository data using Read, Glob, and Grep, it does so within a structured analytical framework designed to identify invariants and failure modes, which naturally serves as a defensive mechanism against untrusted input interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 19, 2026, 01:22 PM
Security Audit — agent-trust-hub — deep-code-intelligence