generate-snapshot

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes a local Python module using the command python -m analysis.snapshot. This is a standard operation for the skill's purpose of analyzing the local repository's health metrics.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external data including git history, source code files, and technical debt comments (TODO/FIXME). While this constitutes an attack surface for indirect prompt injection, the skill is only extracting metrics and generating a structured report, with no evidence of instructions to the agent to treat this data as executable commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 12:54 AM
Security Audit — agent-trust-hub — generate-snapshot