capstone-radar

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Executes standard CLI tools including grep, git, find, and stat to analyze codebase metrics, search for potential issues, and verify project history. These commands are restricted to local repository analysis and are fundamental to the skill's stated auditing purpose.
  • [EXTERNAL_DOWNLOADS]: References the 'Dippy' utility on GitHub (github.com/ldayton/Dippy) as a recommendation for resolving environment-specific permission issues. The link is presented neutrally as a developer resource and does not trigger automated or silent downloads.
  • [DATA_EXFILTRATION]: While the skill scans for patterns matching credentials and secrets, it does so entirely within the local environment for security auditing. No instructions exist to transmit this data to external servers or non-whitelisted domains.
  • [PROMPT_INJECTION]: The skill does not contain instructions that attempt to override model safety guidelines or extract system prompts. It includes explicit verification steps to ensure findings are confirmed by the model rather than blindly reported.
  • [OBFUSCATION]: Analysis of the markdown body and shared core patterns revealed no hidden characters, Base64-encoded instructions, homoglyph substitutions, or other obfuscation techniques.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 09:42 AM
Security Audit — agent-trust-hub — capstone-radar