codebase-design
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze, design, and restructure codebases, which involves processing untrusted external data (source code). This data could contain malicious instructions designed to influence the agent's behavior. The skill possesses capabilities that could be exploited if an injection occurs.
- Ingestion points: User-provided source code, module interfaces, and design requests accessed via
Read,Grep, andGlobtools as specified inSKILL.md. - Boundary markers: The skill does not define explicit delimiters or instructions for the agent to ignore potentially malicious embedded content within the code it analyzes.
- Capability inventory: The
allowed-toolssection inSKILL.mdincludesBash,Write, andEdit, which provide the ability to execute system commands and modify the local filesystem. - Sanitization: There are no procedures defined in the scripts or instructions to sanitize or validate the content of the files before they are processed by the agent.
Audit Metadata