dead-code

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted project source code as input for its static analysis functions.
  • Ingestion points: The tldr tool scans the project directory (.) and source folders (src/) to identify dead code.
  • Boundary markers: The instructions lack specific delimiters or "ignore instructions" directives to prevent the agent from potentially following malicious instructions embedded within the analyzed code comments or strings.
  • Capability inventory: The skill utilizes the Bash tool to execute CLI commands for code analysis and architecture mapping.
  • Sanitization: No sanitization or validation of the codebase content is mentioned prior to ingestion and analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:10 PM
Security Audit — agent-trust-hub — dead-code