dead-code-cleanup
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes codebase content which could harbor malicious instructions designed to trick the agent into deleting legitimate code.
- Ingestion points: Findings from the
get_dead_code()andget_risk()tools (SKILL.md). - Boundary markers: Instructions require the agent to present specific metadata and obtain user confirmation before deletion.
- Capability inventory: Includes tool access for identifying and facilitating the removal of files and exports.
- Sanitization: Safety relies on confidence thresholds and human-in-the-loop review rather than automated input filtering.
Audit Metadata