code-analyzer

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: Architectural Design: The skill is designed specifically for Senior Software Architects to perform static analysis. It emphasizes understanding and explanation over execution or reproduction of source code, which significantly reduces data leakage and execution risks.
  • [SAFE]: Explicit Constraint Patterns: The inclusion of 'Critical Patterns' such as 'Explain, Don't Copy' and 'Explicit Unknowns' provides robust instruction-level guardrails that prevent the agent from hallucinating or improperly handling missing information.
  • [SAFE]: Tool Permission Alignment: The requested tools (Read, Glob, Grep, Bash, Task) are appropriate for the stated purpose of analyzing codebases. The workflow instructions focus on reading and analyzing rather than executing the code under review.
  • [SAFE]: Verified Vendor Infrastructure: All external resource references in the manifest and documentation trace back to the vendor's own verified infrastructure (synapsync.dev) and official GitHub repositories, conforming to safe vendor resource patterns.
  • [SAFE]: Indirect Prompt Injection Surface: Although the skill processes external code, its instructions are limited to generating static documentation (technical reports and refactoring plans). The absence of instructions to execute or dynamically evaluate the processed code effectively mitigates the primary risks associated with indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 02:38 PM