skills/pproenca/dot-skills/ast-grep/Gen Agent Trust Hub

ast-grep

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The README.md file contains instructions to execute pnpm install, which triggers the download of dependencies from the NPM registry. NPM is a well-known service, and this command is a standard part of the development and validation workflow for the skill.
  • [COMMAND_EXECUTION]: The SKILL.md and AGENTS.md files provide numerous examples of CLI commands for ast-grep (e.g., ast-grep scan, ast-grep run). These commands are used to perform structural analysis and apply code transformations, which is the intended and primary use case of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with and process external codebases, creating a surface for indirect prompt injection.
  • Ingestion points: External source code files and directories scanned using ast-grep scan and ast-grep run (referenced in the SKILL.md workflow).
  • Boundary markers: The skill uses standard YAML and CLI syntax to define rules and code snippets, but it does not provide explicit guidance on sanitizing untrusted code to prevent injection into the agent's context or the ast-grep engine.
  • Capability inventory: The skill utilizes the ast-grep tool, which has the capability to read files and write changes back to the filesystem (via the --update-all and --interactive flags).
  • Sanitization: The skill recommends validating all patterns in the official ast-grep playground and using interactive review modes before applying bulk changes to a codebase, which serves as a mitigation against unintended or malicious modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — ast-grep