code-understand

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation suggests installing the @colbymchenry/codegraph package via npm to provide an enhanced backend for code analysis. While it advises the agent to obtain user consent before installation, it facilitates the execution of third-party, unversioned code from an external registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes local project files to build an architecture map, which creates an attack surface where malicious content within those files could potentially influence the agent's reasoning. * Ingestion points: Project source files processed by the obsidian-wiki code-understand command in SKILL.md. * Boundary markers: The skill does not define specific delimiters or instructions to prevent the agent from following directions potentially embedded within the scanned source code. * Capability inventory: Performs file system reads, symbol extraction, and cross-file reference identification. * Sanitization: No validation or sanitization mechanisms are specified for the codebase data being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 12:28 AM
Security Audit — agent-trust-hub — code-understand