kernel-clean-code
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase content which could contain malicious instructions or misleading comments designed to subvert the audit.\n
- Ingestion points: Codebase files being audited or refactored as defined in
ai-slop-cleaner.mdandtech-debt-audit.md.\n - Boundary markers: The skill requires explicit
file:linecitations for all findings and emphasizes evidence-based reporting to mitigate the risk of obeying embedded instructions.\n - Capability inventory: Access to
ReadandWritetools; ability to execute standard ecosystem audit commands (e.g.,git,npm,ruff) via shell tools.\n - Sanitization: Employs regression tests to verify that code behavior remains unchanged during refactoring passes.\n- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill recommends using several well-known and standard development audit tools to perform technical assessments.\n
- Evidence: Mentions tools such as
npm audit,pip-audit,cargo audit,ruff,mypy, andgolangci-lintinreferences/tech-debt-audit.md.\n - Context: These are recognized technology ecosystem tools used for security and quality checks. The skill explicitly advises against installing tools globally without user permission.
Audit Metadata