lumen-instrument
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
bashto scan the local filesystem for analytics configurations inpackage.jsonand grep for tracking calls in source files (.ts,.tsx,.py). These commands are used for context discovery and do not involve remote code execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local project files to inform its instrumentation plan.
- Ingestion points: Reads content from
package.jsonand source code files viagrepinSKILL.md(Step 0). - Boundary markers: None. The agent processes found snippets directly into the analysis context.
- Capability inventory: Access to
Bash,WebFetch,WebSearch, andWritetools. - Sanitization: None detected. Malicious comments or strings in the analyzed codebase could potentially influence the agent's output or tool usage.
Audit Metadata