index-knowledge
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Command Execution: The skill utilizes standard system utilities through
bash(such asfind,awk,sed,wc, andsort) to perform structural analysis and code concentration measurements within the local project directory. These operations are essential for its purpose of mapping the codebase. - Indirect Prompt Injection Surface: The skill ingests content from external sources (existing project documentation and configuration files) to inform the generation of new
AGENTS.mdfiles. This creates a surface where instructions embedded in project files could potentially influence the agent's behavior during the discovery and generation phases. - Ingestion points: The skill reads existing
AGENTS.md,CLAUDE.md, and project configuration files (e.g.,.eslintrc,pyproject.toml,.editorconfig) inSKILL.md. - Boundary markers: There are no explicit delimiters or "ignore embedded instructions" warnings for the ingested content.
- Capability inventory: The skill possesses the ability to execute
bashcommands, spawn subagents viaTaskcalls, and perform file-write operations to the filesystem. - Sanitization: No explicit sanitization, validation, or filtering of the ingested project data is documented before it is processed by the AI.
Audit Metadata