qalam
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill interacts with a local CLI tool to process source code and provide translations.
- [SAFE]: The skill processes local source code files to generate documentation. While this creates a data ingestion surface, the risk of indirect prompt injection is minimal because the skill lacks dangerous capabilities such as network access, privilege escalation, or sensitive file system operations. 1. Ingestion points: source code files in directories specified by the user (SKILL.md); 2. Boundary markers: absent; 3. Capability inventory: subprocess execution of the 'qalam' binary (SKILL.md); 4. Sanitization: absent.
Audit Metadata