module-audit-agent
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill restricts bash command execution to the wednesday-skills CLI tool, which is authored by the same vendor as the skill. This follows the principle of least privilege.
- [INDIRECT_PROMPT_INJECTION]: The skill processes project metadata files, which constitutes a potential attack surface for indirect instructions.
- Ingestion points: dep-graph.json and summaries.json (SKILL.md).
- Boundary markers: None identified in the prompt logic.
- Capability inventory: Uses bash to execute scoring and test generation tools.
- Sanitization: No explicit sanitization or validation of the input JSON content is specified before the agent processes it for the report.
Audit Metadata