code-health

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from source code and coverage reports, which constitutes a surface for indirect prompt injection attacks. • Ingestion points: Repository source files and coverage data files (e.g., LCOV, Cobertura). • Boundary markers: There are no explicit delimiters or instructions for the agent to ignore embedded commands within the analyzed files. • Capability inventory: The agent retrieves analysis results through tools like get_health and get_risk. • Sanitization: No specific sanitization or filtering of the input data is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 09:46 AM
Security Audit — agent-trust-hub — code-health