structure-codebase

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references architectural documentation from trusted organizations such as Vercel (Next.js), Google (Angular), and the Redux maintainers. These references are provided for research purposes and are considered safe.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided codebase content to generate architectural proposals, which constitutes an ingestion surface for potential indirect prompt injection attacks.\n
  • Ingestion points: Files within the analyzed repository, including source code, package manifests, and project documentation, are processed to derive project structure and meaning (as described in SKILL.md).\n
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the analyzed code comments or documents.\n
  • Capability inventory: The skill is capable of proposing repository-wide architecture changes, file placement rules, and migration sequences (as described in SKILL.md).\n
  • Sanitization: The skill does not specify filtering or validation methods for text content or instructions found within the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:12 AM
Security Audit — agent-trust-hub — structure-codebase