monorepo-navigator
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/impact_detector.pyscript uses thesubprocess.runfunction to executegit diffandgit merge-basecommands. This is used to identify changed files within the repository for impact analysis. The script correctly uses list-based arguments for the subprocess calls, which prevents shell command injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local filesystem during its analysis of monorepo structures.
- Ingestion points:
scripts/dependency_graph.py,scripts/impact_detector.py, andscripts/package_analyzer.pyread content frompackage.json,pnpm-workspace.yaml, andlerna.jsonfiles. - Boundary markers: No specific delimiters or "ignore instructions" warnings are used when the agent processes the output of these tools.
- Capability inventory: The tools are capable of reading local files and executing
gitcommands. - Sanitization: The scripts do not perform explicit sanitization of package names or version strings extracted from the configuration files before they are presented to the agent.
Audit Metadata