project-structure-and-packages

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell scripts (scripts/check_structure.sh and scripts/check_import_boundaries.sh) designed to validate the project's directory structure and import rules. These scripts use standard Linux utilities such as grep, find, and sed to perform static analysis on local source code files. The operations are local and do not involve network activity or privileged command execution.
  • [DATA_EXPOSURE]: Analysis of the scripts and instructions shows no attempts to access sensitive system files, environment variables, or credentials. The scope of file access is limited to the project's source directory (defaulting to lib/).
  • [PROMPT_INJECTION]: The instructions in SKILL.md are descriptive and focus on project architecture. There are no patterns suggesting attempts to bypass safety filters or override system instructions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill analyzes external source code provided by users, the scripts only perform pattern matching via grep. They do not interpret or execute the content of the files in a way that would lead to code execution or agent manipulation. The attack surface is minimal and handled through static analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 01:01 PM
Security Audit — agent-trust-hub — project-structure-and-packages