ameba-integration
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external project data (Crystal source code) through the Ameba linter, representing a potential surface for indirect instructions if the analyzed code is malicious.
- Ingestion points: Reads and analyzes local
.crfiles viagit diffandamebacommands. - Boundary markers: The scripts do not implement explicit boundary delimiters or warnings against embedded instructions in the source code.
- Capability inventory: The skill utilizes
Bashfor command execution andReadfor file access. - Sanitization: No specific sanitization or filtering is performed on the files before analysis.
- [DYNAMIC_EXECUTION]: The skill facilitates the creation and execution of local shell scripts to automate Git hooks.
- Evidence: Instructions describe creating shell scripts in
.git/hooks/and applyingchmod +xto enable execution. - [COMMAND_EXECUTION]: Orchestrates the use of standard development tools including
git,xargs,grep, andjqto manage linting results and workflows. - [EXTERNAL_DOWNLOADS]: Configures CI/CD pipelines to download official Crystal language tools and community-standard GitHub Actions.
- Evidence: References official components such as
crystal-lang/install-crystalandcrystal-ameba/github-actionfor environment setup and reporting.
Audit Metadata