connector-audit

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate engineering tool for auditing software connectors. It follows a structured and transparent workflow designed for code quality and reliability improvements.
  • [COMMAND_EXECUTION]: The skill leverages standard developer utilities including git (for history and branch management), gh (GitHub CLI for PR information), and make (for formatting and linting). These are used appropriately for their intended purposes within the project directory.
  • [DYNAMIC_EXECUTION]: During the implementation phase, the agent is instructed to write Python code and execute tests using pytest. This high-privilege behavior is central to the skill's purpose of refactoring and fixing identified issues, and is managed through dry-run options and user review gates.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data in the form of existing connector source code and configuration files. While this represents a potential surface for instructions embedded in code (e.g., in comments), the risk is inherent to code-auditing tasks and is mitigated by the structured investigation prompts and human-in-the-loop validation steps.
  • [DATA_EXPOSURE]: The skill analyzes local repository files and metadata. It does not attempt to access sensitive system paths or exfiltrate information to external domains. Context is maintained in local JSON and Markdown files within the .claude/ directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 08:38 AM
Security Audit — agent-trust-hub — connector-audit