ae-migrate-tracking-code

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a provider-agnostic core logic with specific adapters for third-party platforms. It utilizes a structured Intermediate Representation (IR) to separate the data extraction phase from the code modification phase, which minimizes the risk of unintended side effects.
  • [INDIRECT_PROMPT_INJECTION]: This skill has the attack surface for indirect prompt injection as it ingests untrusted code from a user's repository. 1. Ingestion points: Phase 0 and Phase 1 scan project manifests (e.g., package.json, build.gradle) and source code for SDK call sites. 2. Boundary markers: The skill uses a structured IR schema (scan.json) to delimit extracted data. 3. Capability inventory: The skill utilizes the ae-cli for plan management and performs automated file writes/modifications in Phase 4. 4. Sanitization: All extracted metadata is normalized into specific naming conventions (snake_case) and validated through a secondary tool (ae-cli validate). Risk is assessed as safe given the narrow developmental context and mandatory user confirmation steps before any destructive action or code insertion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:54 AM
Security Audit — agent-trust-hub — ae-migrate-tracking-code