code-review
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill performs local analysis of project files using standard tools.
- [DATA_EXFILTRATION]: The skill reads project source files and CLAUDE.md configuration. This access is local and necessary for its functionality.
- [PROMPT_INJECTION]: The skill analyzes external code which represents an indirect prompt injection surface. Evidence: 1. Ingestion points: reads target files and CLAUDE.md in full. 2. Boundary markers: absent. 3. Capability inventory: Bash, Read, Glob, and Grep tools are enabled. 4. Sanitization: none mentioned in instructions. The risk is minimized as the skill behavior is restricted to analytical reporting.
Audit Metadata