ast-grep-find

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external code files and user-provided search/replace patterns as input for the ast_grep_find.py script, creating a potential surface for indirect prompt injection if processing untrusted data.
  • Ingestion points: The skill reads file content from locations specified by the --path and --glob parameters and processes pattern strings provided via the --pattern argument.
  • Boundary markers: There are no explicit boundary markers, delimiters, or instructions provided to the agent to disregard instructions potentially embedded within the code being analyzed.
  • Capability inventory: The skill utilizes the Bash tool to execute Python scripts that perform file system reads and modifications.
  • Sanitization: The skill instructions do not specify any sanitization, validation, or escaping of the patterns or the content of the files being searched.
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands through uv run python to carry out code analysis and refactoring operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — ast-grep-find