skills/microsoft/waza/code-explainer/Gen Agent Trust Hub

code-explainer

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFE
Full Analysis
  • Passive Analysis Design: The skill functions as a passive code explainer. It processes user-provided snippets within the agent's reasoning context without the use of external tools, network requests, or file system modifications.
  • Absence of Dangerous Commands: A review of the instructions and examples confirms there are no system commands, shell scripts, or dynamic execution patterns that could lead to unauthorized system access or privilege escalation.
  • Data Handling: While the skill is designed to ingest and process user-supplied code (a potential surface for indirect prompt injection), the risk is mitigated by the fact that the skill has no destructive capabilities or data exfiltration paths.
  • Consistent Metadata: The metadata (name, description, and author) accurately reflects the behavior defined in the instructions, with no evidence of deception or metadata poisoning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 02:23 AM
Security Audit — agent-trust-hub — code-explainer