data-model-radar

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes local shell utilities including grep, git log, git diff, and stat to perform structural analysis and metadata extraction from the codebase. These operations are scoped to the local repository and are used to verify audit claims.
  • [EXTERNAL_DOWNLOADS]: The skill contains a reference to an external utility called 'Dippy' on GitHub. This is presented as an optional, manual installation instruction for the user to help handle project paths with spaces, and does not involve automated or hidden downloads by the agent.
  • [PROMPT_INJECTION]: The instructions include 'Anti-shortcut rules' and specific guidance for user interactions (AskUserQuestion), but no evidence of safety bypass attempts or system prompt extraction was found.
  • [DATA_EXFILTRATION]: All findings, session preferences, and audit logs are persisted locally in the .radar-suite and .agents directories within the project root. No patterns for unauthorized network transmission of sensitive code or metadata were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 09:42 AM
Security Audit — agent-trust-hub — data-model-radar