using-static-analysis-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill mentions prompt injection patterns (e.g., 'IGNORE PREVIOUS INSTRUCTIONS') in llm-assisted-rule-explanation.md. These are documented as illustrative examples of threat models for developers to consider when building LLM-enriched features. They are educational in nature and do not represent an attempt to override the agent's behavior.
  • [EXTERNAL_DOWNLOADS]: The documentation references various industry-standard libraries and services such as libcst, tree-sitter, and GitHub for integration and architectural context. These references are neutral and informative, posing no security risk.
  • [SAFE]: The skill is a set of comprehensive design documents for static analysis software. It follows security-by-design principles, addressing topics like dataflow soundness and false-positive economics. No malicious patterns, such as exfiltration, obfuscation, or unauthorized command execution, were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 08:34 PM
Security Audit — agent-trust-hub — using-static-analysis-engineering