project-structure-and-packages
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
scripts/check_structure.shandscripts/check_import_boundaries.sh) designed to validate the project's directory structure and import rules. These scripts use standard Linux utilities such asgrep,find, andsedto perform static analysis on local source code files. The operations are local and do not involve network activity or privileged command execution. - [DATA_EXPOSURE]: Analysis of the scripts and instructions shows no attempts to access sensitive system files, environment variables, or credentials. The scope of file access is limited to the project's source directory (defaulting to
lib/). - [PROMPT_INJECTION]: The instructions in
SKILL.mdare descriptive and focus on project architecture. There are no patterns suggesting attempts to bypass safety filters or override system instructions. - [INDIRECT_PROMPT_INJECTION]: While the skill analyzes external source code provided by users, the scripts only perform pattern matching via
grep. They do not interpret or execute the content of the files in a way that would lead to code execution or agent manipulation. The attack surface is minimal and handled through static analysis.
Audit Metadata