ae-migrate-tracking-code
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a provider-agnostic core logic with specific adapters for third-party platforms. It utilizes a structured Intermediate Representation (IR) to separate the data extraction phase from the code modification phase, which minimizes the risk of unintended side effects.
- [INDIRECT_PROMPT_INJECTION]: This skill has the attack surface for indirect prompt injection as it ingests untrusted code from a user's repository. 1. Ingestion points: Phase 0 and Phase 1 scan project manifests (e.g., package.json, build.gradle) and source code for SDK call sites. 2. Boundary markers: The skill uses a structured IR schema (scan.json) to delimit extracted data. 3. Capability inventory: The skill utilizes the ae-cli for plan management and performs automated file writes/modifications in Phase 4. 4. Sanitization: All extracted metadata is normalized into specific naming conventions (snake_case) and validated through a secondary tool (ae-cli validate). Risk is assessed as safe given the narrow developmental context and mandatory user confirmation steps before any destructive action or code insertion.
Audit Metadata