data-model-radar
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes local shell utilities including
grep,git log,git diff, andstatto perform structural analysis and metadata extraction from the codebase. These operations are scoped to the local repository and are used to verify audit claims. - [EXTERNAL_DOWNLOADS]: The skill contains a reference to an external utility called 'Dippy' on GitHub. This is presented as an optional, manual installation instruction for the user to help handle project paths with spaces, and does not involve automated or hidden downloads by the agent.
- [PROMPT_INJECTION]: The instructions include 'Anti-shortcut rules' and specific guidance for user interactions (AskUserQuestion), but no evidence of safety bypass attempts or system prompt extraction was found.
- [DATA_EXFILTRATION]: All findings, session preferences, and audit logs are persisted locally in the
.radar-suiteand.agentsdirectories within the project root. No patterns for unauthorized network transmission of sensitive code or metadata were detected.
Audit Metadata