tech-leader-agent
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, such as credential harvesting, unauthorized network connections, or persistence mechanisms, were found in the provided files.
- [PROMPT_INJECTION]: The skill is designed to analyze external code for reviews, which creates a surface for indirect prompt injection if the reviewed files contain malicious instructions. However, the skill does not contain any malicious triggers itself.
- [COMMAND_EXECUTION]: The runtime configuration for Claude Code requests broad permissions including
bashandedit. These are standard requirements for a technical lead agent intended to manage project environments and perform code modifications, and are not considered malicious in this context.
Audit Metadata