ameba-integration

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external project data (Crystal source code) through the Ameba linter, representing a potential surface for indirect instructions if the analyzed code is malicious.
  • Ingestion points: Reads and analyzes local .cr files via git diff and ameba commands.
  • Boundary markers: The scripts do not implement explicit boundary delimiters or warnings against embedded instructions in the source code.
  • Capability inventory: The skill utilizes Bash for command execution and Read for file access.
  • Sanitization: No specific sanitization or filtering is performed on the files before analysis.
  • [DYNAMIC_EXECUTION]: The skill facilitates the creation and execution of local shell scripts to automate Git hooks.
  • Evidence: Instructions describe creating shell scripts in .git/hooks/ and applying chmod +x to enable execution.
  • [COMMAND_EXECUTION]: Orchestrates the use of standard development tools including git, xargs, grep, and jq to manage linting results and workflows.
  • [EXTERNAL_DOWNLOADS]: Configures CI/CD pipelines to download official Crystal language tools and community-standard GitHub Actions.
  • Evidence: References official components such as crystal-lang/install-crystal and crystal-ameba/github-action for environment setup and reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 09:01 AM
Security Audit — agent-trust-hub — ameba-integration