quality-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external codebases and AI-generated files, which introduces an inherent surface for indirect prompt injection if the files being reviewed contain malicious embedded instructions.
  • Ingestion points: Untrusted source code, documentation, and codebase files are read into the agent context during Phase 1 (Discovery) as described in SKILL.md and references/audit-rubric.md.
  • Boundary markers: Absent. The instructions lack explicit text delimiters or specific configuration guidelines to isolate codebase contents from the agent's core instructions.
  • Capability inventory: The skill instructions guide the agent to invoke shell execution tools for codebase analysis (rg, npx eslint, npx vitest, npm audit, npm run build) across references/anti-patterns-guide.md, references/audit-rubric.md, and references/verification-gap-protocol.md.
  • Sanitization: Absent. Content from the codebase under review is interpolated directly into the analysis context without filtering or sanitization.
  • [COMMAND_EXECUTION]: The documentation contains multiple predefined command-line strings meant for codebase linting, static analysis, and testing.
  • Evidence: Files references/anti-patterns-guide.md, references/audit-rubric.md, and references/verification-gap-protocol.md contain instructions for running rg, npx eslint, npx vitest, npm audit, and npm run build to gather evidence metrics.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing an optional vendor-owned dependency if a related workflow is required.
  • Evidence: In SKILL.md, the instruction suggests executing pnpm dlx skills add oakoss/agent-skills -s usability-tester -a claude-code -y to acquire a peer skill. This points directly to the author's own namespace (oakoss) and is recognized as legitimate vendor resource behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:50 AM
Security Audit — agent-trust-hub — quality-auditor