sync-validate

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze untrusted project source code, which constitutes a potential injection surface.
  • Ingestion points: Reads src/index.ts and other imported modules in the project using Read and Grep.
  • Boundary markers: The instructions do not define delimiters or warnings to ignore instructions that might be embedded in the analyzed code.
  • Capability inventory: The skill uses Read, Glob, Grep, and Bash to interact with the environment.
  • Sanitization: The agent processes raw source code strings without specific sanitization or escaping mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:37 AM
Security Audit — agent-trust-hub — sync-validate