ax-audit
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit untrusted source code and pull request diffs. This creates a surface for indirect prompt injection where malicious code comments or identifiers could attempt to influence the agent's audit findings. Specifically, the skill supports suppression comments (e.g.,
ax-audit-ignore:<slug>), which are intended for legitimate use but could be abused by an attacker to hide security flaws from the auditor. - Ingestion points: PR merge-base diffs and explicit file paths defined in SKILL.md.
- Boundary markers: The instructions do not specify strict delimiters for untrusted code input.
- Capability inventory: The skill uses
rg(ripgrep) for searching and standard file read operations. - Sanitization: There is no explicit sanitization of the input code; the skill relies on the agent's interpretation of grep results.
- [COMMAND_EXECUTION]: The skill workflow involves the agent executing shell commands (primarily
rg) that are defined within the rule files (e.g.,rules-arch/comm-no-approval-gate.md). This is a standard pattern for developer-oriented tools and is used here for searching code patterns related to agent-native architecture and experience.
Audit Metadata