legacy-modernizer

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No high-risk patterns such as command execution, data exfiltration, or obfuscation were detected. The skill uses a passive instructional approach.\n- [PROMPT_INJECTION]: The skill has a potential surface for indirect prompt injection, though it is assessed as safe due to the absence of exploitable tools.\n
  • Ingestion points: The agent is tasked with "Analyze codebase" and "Review technical debt" in SKILL.md.\n
  • Boundary markers: Not present; the instructions do not provide explicit delimiters for untrusted data.\n
  • Capability inventory: The skill specifies allowed-tools: '', which prevents the agent from performing potentially harmful actions on the system.\n
  • Sanitization: No sanitization of code comments or documentation is performed.\n- [NO_CODE]: The skill does not include any Python or Node.js scripts, nor does it specify any external package dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 04:15 AM
Security Audit — agent-trust-hub — legacy-modernizer