constant-time-analysis

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local Python tool (analyzer.py) to invoke system compilers and disassemblers—such as gcc, clang, javac, and node—to inspect the low-level execution characteristics of cryptographic source code.
  • [PROMPT_INJECTION]: By processing user-provided source code for analysis, the skill has an indirect prompt injection surface. This is addressed through instructions for manual verification of findings and detailed triage procedures to distinguish between true vulnerabilities and false positives.
  • [EXTERNAL_DOWNLOADS]: The reference guides provide instructions for the user to install necessary development tools and extensions from well-known and trusted sources, including official language distribution sites, established package managers, and reputable GitHub repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:19 PM
Security Audit — agent-trust-hub — constant-time-analysis