codebase-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted codebases as part of its analysis process. While this represents a theoretical surface for indirect prompt injection (e.g., if source code files contains malicious instructions intended for the agent), the provided scripts (architecture_mapper.py, onboarding_generator.py, and setup_validator.py) only perform structural and metadata analysis, such as counting lines and parsing manifest files (e.g., package.json), rather than executing or semantically processing arbitrary code. This design inherently limits the success of injection attempts.
  • [COMMAND_EXECUTION]: The skill uses Python scripts and recomended shell commands (like find, grep, and wc) to gather information about a project's directory structure and tech stack. These operations are restricted to the local file system and target the project's own files. The analysis does not involve executing untrusted input or system-level modifications.
  • [SAFE]: The setup_validator.py script specifically includes a security feature that checks if .env files are excluded from version control, providing a warning if it detects potentially committed credentials. This demonstrates a security-conscious design intended to protect user secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 08:10 AM
Security Audit — agent-trust-hub — codebase-onboarding