skills/othmanadi/apex/apex-decompose/Gen Agent Trust Hub

apex-decompose

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate code analysis tasks using local scripts. No evidence of malicious intent, data exfiltration, or obfuscation was found during the audit.\n- [INDIRECT_PROMPT_INJECTION]: The skill reads source code from a user-specified directory, which is a potential surface for indirect prompt injection attacks where malicious content in source code could influence the agent.\n
  • Ingestion points: Source code files and dependency manifests are read from the user-provided directory in SKILL.md and by the analysis scripts in the scripts/ directory.\n
  • Boundary markers: The instructions do not define specific delimiters or warnings for the agent to ignore instructions embedded within the ingested source code.\n
  • Capability inventory: The skill has capabilities to read local files and write specification documents to the specs/ directory.\n
  • Sanitization: No sanitization or content filtering is applied to the source code before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:44 AM
Security Audit — agent-trust-hub — apex-decompose