codemap
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local system commands
gitandmadgeto analyze the project structure and dependencies. - [EXTERNAL_DOWNLOADS]: Recommends the installation of the
madgepackage from the npm registry and utilizesnpx tsxfor script execution. - [INDIRECT_PROMPT_INJECTION]: The skill processes arbitrary code and documentation files within a project directory, which could contain malicious instructions if the analyzed repository is untrusted.
- Ingestion points: The script reads project file names and content from the local file system using
fs.readFileSyncandgit ls-filesinscripts/codemap.ts. - Boundary markers: The generated Markdown and PlantUML reports do not employ explicit boundary markers or warnings to isolate processed data from agent instructions.
- Capability inventory: The skill has the ability to write files to the project directory and execute local CLI tools such as
gitandmadge. - Sanitization: The script performs basic sanitization of strings used for PlantUML identifiers to prevent syntax errors.
Audit Metadata