skills/techygarg/lattice/clean-code/Gen Agent Trust Hub

clean-code

Pass

Audited by Gen Agent Trust Hub on May 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill primarily provides logic for code quality analysis and refactoring. No malicious patterns such as remote code execution, persistence, or privilege escalation were detected.
  • [PROMPT_INJECTION]: The skill implements a 'Config Resolution' system that reads .lattice/config.yaml and related project documentation to override or extend default behaviors. This mechanism allows the agent to ingest external instructions from the repository, creating an indirect prompt injection surface. However, this is used for legitimate project-specific adaptation and does not involve high-risk capabilities. * Ingestion points: Repository root .lattice/config.yaml and custom documentation paths defined therein. * Boundary markers: None explicitly defined in the skill instructions to delimit project-provided configuration from the system prompt. * Capability inventory: Limited to text generation, refactoring, and code modification. * Sanitization: The skill does not perform sanitization on the content of loaded project configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — clean-code