lint-and-validate

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/lint_runner.py script executes common developer tools like npm, ruff, and mypy using secure subprocess calls that prevent shell injection.
  • [DATA_EXFILTRATION]: Analysis scripts read local project metadata and source code to generate reports; however, no network operations or external data transfer mechanisms are present.
  • [PROMPT_INJECTION]: Instructions in SKILL.md define a mandatory validation workflow for the agent. These constraints are task-oriented and do not attempt to override the model's safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 03:04 AM