codeknit-parse

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to parse and analyze external source code files, which creates a surface for indirect prompt injection. Maliciously crafted source code (e.g., specific symbol names, comments, or metadata) could attempt to influence the agent's behavior when it reads the extracted structure.
  • Ingestion points: The <input-path> provided to codeknit parse and codeknit graph analyze in SKILL.md.
  • Boundary markers: The output is structured into .skt or JSON formats with defined sections ([symbols], [edges], [errors]), which helps the agent distinguish between tool metadata and user-provided code data.
  • Capability inventory: The skill utilizes the codeknit CLI tool to perform file system analysis and structure extraction.
  • Sanitization: The tool converts raw code into a structured intermediate format, but the skill does not explicitly describe filters or sanitization logic for the content of symbol signatures or names.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the codeknit CLI tool via several subcommands (parse, graph analyze). These commands interact with the local file system to read source files and write analysis reports to a ./skeleton directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 12:32 AM
Security Audit — agent-trust-hub — codeknit-parse