irify-sast
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions require the user to configure a Model Context Protocol (MCP) server by running the
yakcommand with specific arguments (yak mcp -t ssa). This involves local command execution on the host system to enable the core static analysis engine. - [INDIRECT_PROMPT_INJECTION]: As a static analysis tool, this skill is designed to ingest and process untrusted source code from various projects. This creates an inherent attack surface where malicious instructions could be embedded in the analyzed codebases, although the risk is mitigated by the AI agent's internal guardrails and the specialized nature of the SSA engine's output.
- Ingestion points: Project source files are loaded via the
ssa_compiletool and explored usingGlobandReadtools. - Boundary markers: The skill relies on the AI agent to interpret the results of
ssa_queryand does not define specific output delimiters for analyzed content. - Capability inventory: The skill possesses the ability to read arbitrary files, perform global searches, and execute complex data flow queries across the filesystem.
- Sanitization: The skill focuses on detection logic; sanitization of the processed data is handled by the underlying LLM's safety layers.
- [DYNAMIC_EXECUTION]: The skill utilizes a custom Domain Specific Language (DSL) called SyntaxFlow. The
ssa_querytool executes these rules against the project's intermediate representation. The language includes advanced features such as<eval>, which allows for the dynamic execution of SyntaxFlow rule strings at runtime.
Audit Metadata