codometer-configure

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a documentation guide for configuring the codometer tool. It provides valid TypeScript examples for managing repository metrics such as file size, line counts, and JSDoc comment budgets.
  • [DYNAMIC_EXECUTION]: The documented configuration format supports a write callback function for custom Markdown reporting. While this allows for code execution during the reporting phase, it is presented as a standard extension point for the tool's functionality and does not involve unsafe dynamic loading or remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The tool includes features to scan and measure prose in source code comments against defined word or line budgets. Although this involves processing untrusted content from the codebase, the skill focuses on quantitative analysis (counting words) rather than interpreting the text as instructions, minimizing the risk of prompt injection through these data channels.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:18 PM
Security Audit — agent-trust-hub — codometer-configure