astcount-verified-refactor-loop

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the astcount tool via bunx astcount@0.2.0 or nix run github:wokalski/astcount/v0.2.0 if it is not already installed locally. These resources are maintained by the skill author.\n- [REMOTE_CODE_EXECUTION]: Executes code from a remote GitHub repository using nix run.\n- [COMMAND_EXECUTION]: Executes user-defined shell commands for testing and runs the astcount measurement tool.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes project files and command output, creating an indirect prompt injection surface.\n
  • Ingestion points: Local source code files and output from the user-provided test command.\n
  • Boundary markers: No specific boundary markers or safety instructions are used for the ingested content.\n
  • Capability inventory: The skill has the capability to modify repository files and execute arbitrary shell commands (test gate).\n
  • Sanitization: No validation or sanitization of the processed code or shell output is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 07:53 PM
Security Audit — agent-trust-hub — astcount-verified-refactor-loop