codebase-design

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze, design, and restructure codebases, which involves processing untrusted external data (source code). This data could contain malicious instructions designed to influence the agent's behavior. The skill possesses capabilities that could be exploited if an injection occurs.
  • Ingestion points: User-provided source code, module interfaces, and design requests accessed via Read, Grep, and Glob tools as specified in SKILL.md.
  • Boundary markers: The skill does not define explicit delimiters or instructions for the agent to ignore potentially malicious embedded content within the code it analyzes.
  • Capability inventory: The allowed-tools section in SKILL.md includes Bash, Write, and Edit, which provide the ability to execute system commands and modify the local filesystem.
  • Sanitization: There are no procedures defined in the scripts or instructions to sanitize or validate the content of the files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:14 PM
Security Audit — agent-trust-hub — codebase-design