rightcode-codeprobe-framework
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, hardcoded credentials, or unauthorized network operations were identified. The tool's operations are consistent with its purpose as a static analysis framework.
- [INDIRECT_PROMPT_INJECTION]: The skill scans external project source code which serves as an untrusted data ingestion point.
- Ingestion points: Framework files and project source files (e.g., composer.json, package.json, .tsx, .php, .py) accessed via Read, Grep, and Glob tools.
- Boundary markers: Absent. The instructions do not specify the use of XML tags or explicit "ignore embedded instructions" delimiters when processing code content.
- Capability inventory: The skill utilizes the Bash tool to perform its auditing logic, which could be exploited if malicious content in audited files influences the agent's command construction.
- Sanitization: Absent. There is no mention of content sanitization or validation of the files being read prior to analysis.
Audit Metadata