ast-grep-find
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external code files and user-provided search/replace patterns as input for the
ast_grep_find.pyscript, creating a potential surface for indirect prompt injection if processing untrusted data. - Ingestion points: The skill reads file content from locations specified by the
--pathand--globparameters and processes pattern strings provided via the--patternargument. - Boundary markers: There are no explicit boundary markers, delimiters, or instructions provided to the agent to disregard instructions potentially embedded within the code being analyzed.
- Capability inventory: The skill utilizes the
Bashtool to execute Python scripts that perform file system reads and modifications. - Sanitization: The skill instructions do not specify any sanitization, validation, or escaping of the patterns or the content of the files being searched.
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute shell commands through
uv run pythonto carry out code analysis and refactoring operations.
Audit Metadata