clean-code

Warn

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses the YAML frontmatter field priority: CRITICAL to influence the agent's internal task prioritization and importance ranking.
  • [PROMPT_INJECTION]: The instructions use high-pressure and mandatory language (e.g., 'CRITICAL', 'MANDATORY', '🔴 VIOLATION') designed to override default agent behavior and ensure strict adherence to the author's workflow.
  • [COMMAND_EXECUTION]: The 'Verification Scripts' section provides a mapping that mandates the execution of Python scripts via the shell (e.g., python ~/.Codex/skills/frontend-design/scripts/ux_audit.py .). These scripts reside in external directories outside the skill's control and are executed with agent permissions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — clean-code