Passed all audits
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill performs repository auditing by executing git commands and reading project configuration files to maintain a local knowledge base. While it ingests untrusted data from the codebase which presents a surface for indirect prompt injection, it lacks dangerous capabilities like network access or arbitrary code execution.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues