lumen-instrument

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses bash to scan the local filesystem for analytics configurations in package.json and grep for tracking calls in source files (.ts, .tsx, .py). These commands are used for context discovery and do not involve remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the local project files to inform its instrumentation plan.
  • Ingestion points: Reads content from package.json and source code files via grep in SKILL.md (Step 0).
  • Boundary markers: None. The agent processes found snippets directly into the analysis context.
  • Capability inventory: Access to Bash, WebFetch, WebSearch, and Write tools.
  • Sanitization: None detected. Malicious comments or strings in the analyzed codebase could potentially influence the agent's output or tool usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — lumen-instrument