finding-discovery
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- Command Execution: The skill utilizes bundled Python scripts to assist in the analysis workflow.
- Evidence:
SKILL.mdspecifies the use of<python_command> <plugin_dir>/scripts/generate_rank_input.pyfor tasks such as generating rank inputs and copying review data. - Indirect Prompt Injection Surface: The tool processes untrusted repository content which is a standard part of security auditing.
- Ingestion points: Source files and commit messages defined in
SKILL.md. - Boundary markers: Workflows are governed by referenced policy files like
scan-artifacts-and-ledger.md. - Capability inventory: Local file reading and script execution using environment placeholders.
- Sanitization: Instructions advise the agent to verify the actual code logic rather than relying on potentially misleading commit narratives.
Audit Metadata