assertion-quality
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions do not contain any malicious patterns such as prompt injection, obfuscation, or data exfiltration. The workflow is restricted to reading and analyzing code files to produce a metrics report.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted test and production code provided by the user (Step 2 and Step 3). However, the risk is negligible because the skill lacks high-privilege capabilities such as network access, file system writing, or arbitrary command execution, and its output is limited to markdown reporting. This is a characteristic of its primary intended purpose and does not represent a vulnerability in the context of its execution environment.
Audit Metadata