ln-652-transaction-correctness-auditor

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches audit contracts, detection methodologies, and report templates from the author's GitHub repository (levnikolaevich/claude-code-skills) when local files are unavailable.
  • [COMMAND_EXECUTION]: Employs the Bash tool to run search operations using Grep and Glob to identify database transaction patterns and triggers in the codebase.
  • [PROMPT_INJECTION]: Features an indirect prompt injection surface through the ingestion of external codebase files and database migrations. Evidence includes: 1. Ingestion points: Reads source code and migration files from the local environment. 2. Boundary markers: Does not explicitly define delimiters to isolate external code content from agent instructions. 3. Capability inventory: File system reading and searching, Bash command execution, and file writing for reporting. 4. Sanitization: No evidence of sanitization or validation of the processed codebase content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 07:48 AM