research-codebase

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes local project validation and session management scripts located in ${CLAUDE_PLUGIN_ROOT}/scripts/ for initialization and tracking.
  • [COMMAND_EXECUTION]: Interacts with project management and version control systems using the GitHub CLI (gh) and the linearis integration tool.
  • [DATA_EXFILTRATION]: Performs automated synchronization of generated research documents to a remote service using the humanlayer thoughts sync command as a primary workflow step.
  • [EXTERNAL_DOWNLOADS]: Retrieves codebase context and architectural information from an external MCP service using the mcp__deepwiki__ask_question tool.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and summarizes untrusted codebase content.
  • Ingestion points: Reads files and documentation via the Read tool.
  • Boundary markers: None explicitly defined for isolating ingested code content.
  • Capability inventory: File system access, shell command execution, and network-based data synchronization.
  • Sanitization: No content sanitization is applied before the agent processes or summarizes the codebase data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 12:58 AM
Security Audit — agent-trust-hub — research-codebase