e2e-reviewer

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/scope-graph.py invokes subprocess.Popen to execute a bundled bash helper script (scripts/scope-source.sh). This is part of the skill's core functionality for performing lexical analysis of the target repository and does not execute arbitrary user input.
  • [DYNAMIC_EXECUTION]: The script scripts/scope-watch.py uses ctypes.CDLL to access the Darwin libSystem library for filesystem probing (fstatfs64). This is used to optimize directory watching on macOS APFS filesystems and is a benign use of dynamic loading for system integration.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted code from external repositories. It includes a mandatory 'Untrusted-input boundary' section in its instructions, directing the AI to treat all target content as untrusted data and explicitly forbidding the execution of commands, reading of secrets, or following of URLs found within the reviewed code.
  • [EXTERNAL_DOWNLOADS]: The skill mentions optional integration with ast-grep and npm registries. It specifies that these are non-mandatory and, when used, are executed with security flags such as disabling lifecycle scripts to prevent supply chain attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:37 PM
Security Audit — agent-trust-hub — e2e-reviewer