monorepo-navigator

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/impact_detector.py script uses the subprocess.run function to execute git diff and git merge-base commands. This is used to identify changed files within the repository for impact analysis. The script correctly uses list-based arguments for the subprocess calls, which prevents shell command injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local filesystem during its analysis of monorepo structures.
  • Ingestion points: scripts/dependency_graph.py, scripts/impact_detector.py, and scripts/package_analyzer.py read content from package.json, pnpm-workspace.yaml, and lerna.json files.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are used when the agent processes the output of these tools.
  • Capability inventory: The tools are capable of reading local files and executing git commands.
  • Sanitization: The scripts do not perform explicit sanitization of package names or version strings extracted from the configuration files before they are presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:27 AM
Security Audit — agent-trust-hub — monorepo-navigator