skill-audit

Pass

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a transparent and logical methodology for software auditing and contains no evidence of malicious code, obfuscation, or unauthorized data collection.
  • [PROMPT_INJECTION]: As a tool designed to ingest and analyze external codebase data, the skill presents an indirect prompt injection surface. Malicious content within the audited files could attempt to influence the agent's behavior or bias the final audit report.
  • Ingestion points: Files identified and read through Glob and Grep searches in the codebase discovery phase (SKILL.md).
  • Boundary markers: The skill does not define explicit delimiters or 'ignore' instructions to isolate the audited code from the agent's operational logic.
  • Capability inventory: The skill utilizes file search tools (Glob, Grep), user interaction (AskUserQuestion), and task tracking (TodoWrite).
  • Sanitization: There are no mentioned mechanisms for sanitizing or escaping content retrieved from the audited files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 17, 2026, 07:19 AM
Security Audit — agent-trust-hub — skill-audit