skills/simota/agent-skills/zen/Gen Agent Trust Hub

zen

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends using several standard development utilities and references documentation from trusted sources.
  • Tool Installation: It provides commands to run or install tools via npx (eslint, knip, depcheck) and go install (deadcode). These target official package registries for NPM and Golang.
  • Trusted Documentation: References are provided to official documentation and research from trusted organizations including GitHub, IBM, Cloudflare (via Vercel Labs repositories), and well-known projects like Knip and SonarQube.
  • [COMMAND_EXECUTION]: The skill includes instructions to execute various command-line analysis tools to measure code quality.
  • Complexity Metrics: Uses tools like lizard, radon, gocyclo, gocognit, cargo clippy, pmd, and checkstyle to calculate cyclomatic and cognitive complexity.
  • Static Analysis: Recommends running eslint, tsc, pylint, staticcheck, and ruff for linting and type checking.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process code, which represents a surface for indirect prompt injection if the code contains malicious instructions.
  • Mitigation: The skill includes robust guardrails, explicitly instructing the agent to never change logic or behavior, to run tests before and after changes, and to route potential security findings to a specialized agent (Judge).
  • Evidence Chain:
  • Ingestion points: Files and functions targetted for refactoring (specified in SKILL.md).
  • Boundary markers: Explicit instructions to "Preserve behavior" and "Stay inside the scope tier".
  • Capability inventory: Shell execution of analysis tools and file system modifications for refactoring.
  • Sanitization: Relies on the agent platform's tool-calling logic to handle parameters safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — zen