complexity-optimizer
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The internal testing script (
scripts/test_analyze_complexity.py) usessubprocess.runto validate the scanner CLI. The command is restricted to running the skill's own bundled Python script with controlled arguments, posing no risk to the host system. - [COMMAND_EXECUTION]: The workflow instructions advise the agent to identify and run existing build and test commands within the analyzed repository. This is an expected operational capability for an optimization tool and relies on the security of the target repository's environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and scan external source code, creating a surface for potential indirect prompt injection. This risk is well-mitigated by the instructions, which mandate strict adherence to a safety checklist, established baseline testing, and preservation of existing behavior.
Audit Metadata