index-knowledge

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill utilizes standard system utilities through bash (such as find, awk, sed, wc, and sort) to perform structural analysis and code concentration measurements within the local project directory. These operations are essential for its purpose of mapping the codebase.
  • Indirect Prompt Injection Surface: The skill ingests content from external sources (existing project documentation and configuration files) to inform the generation of new AGENTS.md files. This creates a surface where instructions embedded in project files could potentially influence the agent's behavior during the discovery and generation phases.
  • Ingestion points: The skill reads existing AGENTS.md, CLAUDE.md, and project configuration files (e.g., .eslintrc, pyproject.toml, .editorconfig) in SKILL.md.
  • Boundary markers: There are no explicit delimiters or "ignore embedded instructions" warnings for the ingested content.
  • Capability inventory: The skill possesses the ability to execute bash commands, spawn subagents via Task calls, and perform file-write operations to the filesystem.
  • Sanitization: No explicit sanitization, validation, or filtering of the ingested project data is documented before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:39 PM
Security Audit — agent-trust-hub — index-knowledge