codegraph-ast-grep

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to execute code from remote sources using runners such as uvx (targeting the ast-grep-mcp repository on GitHub) and npx (targeting the codegraph package).
  • [EXTERNAL_DOWNLOADS]: The setup instructions include commands to download and install packages from public registries and repositories using standard package managers including npm, pnpm, yarn, bun, brew, cargo, and pip.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands for environment discovery, tool verification, and repository status checks, including command -v, git status, and version queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 09:20 AM
Security Audit — agent-trust-hub — codegraph-ast-grep