codemap
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the repository being mapped, creating a surface for indirect prompt injection.
- Ingestion points: The
codemap.mjsscript and "fixer" agents read arbitrary files within the repository to compute hashes and generate architectural summaries (Workflow described inSKILL.mdStep 2.4 and Step 3.3). - Boundary markers: The instructions lack specific boundary markers or warnings to the agents to ignore potential embedded instructions within the code being documented.
- Capability inventory: The skill has the capability to write files (
codemap.md,.slim/codemap.json) and modify repository configuration (AGENTS.mdinSKILL.mdStep 5) which is used to influence future agent sessions. - Sanitization: The workflow does not specify any sanitization or validation of the content extracted from the source files before it is used to populate documentation templates.
- [COMMAND_EXECUTION]: The skill instructions require the agent to execute a local Node.js script (
codemap.mjs) to perform repository scanning and state management (Workflow inSKILL.mdStep 2.3 and Step 3).
Audit Metadata