finder
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a read-only research assistant. It lacks the ability to execute commands, install packages, or modify repository files, which effectively mitigates most common attack vectors.
- [DATA_EXPOSURE]: The skill includes instructions to research the local repository to align external findings with existing code conventions. While this involves reading local files, the instructions emphasize that the tool is advisory, and it does not possess the capability to exfiltrate this data or perform unauthorized network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill fetches content from untrusted external sources (web pages, community discussions) which could theoretically contain malicious instructions. However, the risk is negligible because the skill lacks exploitable capabilities such as file writing, shell access, or code execution. The agent acts purely as a synthesizer of information for human review.
- [NO_CODE]: The skill consists entirely of natural language instructions and markdown templates. It does not ship with any scripts, binaries, or configuration files that could be used for malicious purposes.
Audit Metadata