NYC

code-simplifier

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION] (LOW): The skill identifies a surface for indirect prompt injection by processing external code for simplification. \n
  • Ingestion points: Untrusted code snippets provided by users (SKILL.md). \n
  • Boundary markers: Instructions emphasize 'Preserve Functionality' and 'Never change what the code does', providing logical but not technical boundaries. \n
  • Capability inventory: No subprocess calls, network operations, or sensitive file access. \n
  • Sanitization: No explicit sanitization or escaping of input code is defined. \n- [SAFE] (SAFE): No hidden payloads, obfuscation (Category 3), or credential exfiltration patterns (Category 2) were found in the provided files. \n- [REMOTE_CODE_EXECUTION] (SAFE): The skill does not include any commands for downloading or executing remote code or packages (Category 4).
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:09 PM