agent-analyze-code-quality
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and analyze source code files, which serves as a primary ingestion point for untrusted data.
- Ingestion points: The skill accesses project files in directories such as
src/**,lib/**, andapp/**, specifically targeting.js,.ts,.py,.java, and.goextensions. - Boundary markers: There are no explicit instructions or delimiters defined to help the agent distinguish between its own instructions and natural language instructions that might be embedded within the source code comments or strings of the files being analyzed.
- Capability inventory: The agent has access to
Read,Grep,Glob, andWebSearchtools, allowing it to process and potentially act on content found within the analyzed files. - Sanitization: No sanitization or validation mechanisms are implemented for the external content before it is interpolated into the agent's context for analysis.
- [COMMAND_EXECUTION]: The skill utilizes shell hooks to automate environment discovery during the initialization phase.
- Execution method: The
pre_executionhook executes a series of shell commands includingfind,grep,wc,xargs, andlsto identify files and locate configuration files. - Evidence: The command
ls -la .eslintrc* .prettierrc* .pylintrc tslint.json 2>$dev$nullcontains an unconventional redirection (2>$dev$null) which may be a typographical error for/dev/nullor an attempt to redirect error output to a variable-controlled path. - [METADATA_POISONING]: The skill's internal metadata contains deceptive information regarding its origin.
- Evidence: The metadata field
authoris set to "Claude Code", which conflicts with the actual author attribution. This represents a deceptive metadata pattern that could lead a user to misjudge the skill's source and safety profile.
Audit Metadata