codebase-mapper
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed to map a codebase by scanning directory structures and sampling file contents (limited to the first 20 lines). These actions are consistent with its stated purpose of documentation and orientation. No network access, remote code execution, or credential harvesting patterns were detected. The skill operates exclusively on the local repository and writes its output to a specific subdirectory.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes external data from the repository. Ingestion points: Reads directory names and the first 20 lines of key project files (Step 1, 3). Boundary markers: None implemented. Capability inventory: File system read/write and directory listing. Sanitization: None implemented. The risk is minimized by the skill's restricted scanning depth and sampling limits, making it safe for its intended purpose.
Audit Metadata