explore-and-document

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill defines a structured, multi-phase workflow for understanding unfamiliar codebases using a suite of integrated tools.
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection through its code ingestion process.
  • Ingestion points: Code content is retrieved via the Read tool and mcp__julie search/symbol tools as described in SKILL.md.
  • Boundary markers: There are no instructions defining boundaries between code data and agent instructions.
  • Capability inventory: The skill provides capabilities to read the file system and write persistent plans and checkpoints via the mcp__goldfish toolset.
  • Sanitization: The skill does not perform sanitization on the codebase content it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 11:10 AM