skills/mblode/agent-skills/ax-audit/Gen Agent Trust Hub

ax-audit

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit untrusted source code and pull request diffs. This creates a surface for indirect prompt injection where malicious code comments or identifiers could attempt to influence the agent's audit findings. Specifically, the skill supports suppression comments (e.g., ax-audit-ignore:<slug>), which are intended for legitimate use but could be abused by an attacker to hide security flaws from the auditor.
  • Ingestion points: PR merge-base diffs and explicit file paths defined in SKILL.md.
  • Boundary markers: The instructions do not specify strict delimiters for untrusted code input.
  • Capability inventory: The skill uses rg (ripgrep) for searching and standard file read operations.
  • Sanitization: There is no explicit sanitization of the input code; the skill relies on the agent's interpretation of grep results.
  • [COMMAND_EXECUTION]: The skill workflow involves the agent executing shell commands (primarily rg) that are defined within the rule files (e.g., rules-arch/comm-no-approval-gate.md). This is a standard pattern for developer-oriented tools and is used here for searching code patterns related to agent-native architecture and experience.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:50 PM
Security Audit — agent-trust-hub — ax-audit