fix-types

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing external Python source code and mypy error logs.
  • Ingestion points: Python source code files and terminal output from the 'uv run mypy' command as described in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters to separate untrusted code content from its core instructions.
  • Capability inventory: The skill utilizes the Bash tool for running type checks and possesses the capability to modify project files to apply fixes.
  • Sanitization: No data validation, escaping, or filtering is applied to the code or tool output before analysis.
  • Mitigation: The primary safeguard is a strict human-in-the-loop requirement, ensuring no fixes are applied without explicit user review and approval.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:09 PM
Security Audit — agent-trust-hub — fix-types