rightcode-codeprobe-framework

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, hardcoded credentials, or unauthorized network operations were identified. The tool's operations are consistent with its purpose as a static analysis framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans external project source code which serves as an untrusted data ingestion point.
  • Ingestion points: Framework files and project source files (e.g., composer.json, package.json, .tsx, .php, .py) accessed via Read, Grep, and Glob tools.
  • Boundary markers: Absent. The instructions do not specify the use of XML tags or explicit "ignore embedded instructions" delimiters when processing code content.
  • Capability inventory: The skill utilizes the Bash tool to perform its auditing logic, which could be exploited if malicious content in audited files influences the agent's command construction.
  • Sanitization: Absent. There is no mention of content sanitization or validation of the files being read prior to analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 10:55 AM
Security Audit — agent-trust-hub — rightcode-codeprobe-framework