kernel-clean-code

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase content which could contain malicious instructions or misleading comments designed to subvert the audit.\n
  • Ingestion points: Codebase files being audited or refactored as defined in ai-slop-cleaner.md and tech-debt-audit.md.\n
  • Boundary markers: The skill requires explicit file:line citations for all findings and emphasizes evidence-based reporting to mitigate the risk of obeying embedded instructions.\n
  • Capability inventory: Access to Read and Write tools; ability to execute standard ecosystem audit commands (e.g., git, npm, ruff) via shell tools.\n
  • Sanitization: Employs regression tests to verify that code behavior remains unchanged during refactoring passes.\n- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill recommends using several well-known and standard development audit tools to perform technical assessments.\n
  • Evidence: Mentions tools such as npm audit, pip-audit, cargo audit, ruff, mypy, and golangci-lint in references/tech-debt-audit.md.\n
  • Context: These are recognized technology ecosystem tools used for security and quality checks. The skill explicitly advises against installing tools globally without user permission.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 10:58 PM
Security Audit — agent-trust-hub — kernel-clean-code