structure-codebase
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references architectural documentation from trusted organizations such as Vercel (Next.js), Google (Angular), and the Redux maintainers. These references are provided for research purposes and are considered safe.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided codebase content to generate architectural proposals, which constitutes an ingestion surface for potential indirect prompt injection attacks.\n
- Ingestion points: Files within the analyzed repository, including source code, package manifests, and project documentation, are processed to derive project structure and meaning (as described in SKILL.md).\n
- Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the analyzed code comments or documents.\n
- Capability inventory: The skill is capable of proposing repository-wide architecture changes, file placement rules, and migration sequences (as described in SKILL.md).\n
- Sanitization: The skill does not specify filtering or validation methods for text content or instructions found within the codebase.
Audit Metadata