decomplex
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill is designed for static analysis of code complexity and lacks network capabilities or unsafe file operations.
- [COMMAND_EXECUTION]: The validation section contains commands like npx and node. These are common developer tools for verification and are not intended for autonomous use by the agent.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests untrusted code and designs from project files. However, security risk is mitigated by (1) ingestion points limited to reviewed artifacts, (2) boundary markers in the report template, (3) a capability inventory restricted to local file writing, and (4) sanitization via instructions that enforce target immutability and advisory-only output.
Audit Metadata