godot-analyst

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious behavior, obfuscation, or unauthorized exfiltration patterns were detected in the skill's instructions or provided scripts.
  • [COMMAND_EXECUTION]: The skill uses local scoring scripts to perform static analysis on Godot project files. These scripts, including score_modernity.py and bottleneck_scanner.gd, are intended to calculate architectural metrics and do not involve network-based execution.
  • [PROMPT_INJECTION]: The skill ingests untrusted data by reading Godot scripts and documentation (docstrings) for analysis. While this presents a surface for indirect prompt injection, it is a functional requirement of the auditing process. No active exploit patterns were found in the provided rubrics.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 01:49 PM
Security Audit — agent-trust-hub — godot-analyst