ccx-codebase-explorer
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions (in
references/management.md) recommend installing thecocoindex-code-pluspackage from the public PyPI registry usinguv,pipx, orpip. This is a vendor-provided tool required for the skill's functionality. - [COMMAND_EXECUTION]: The agent is instructed to execute the
ccxCLI tool for various codebase exploration tasks, includingsearch,grep,defs,refs, andask. These commands interact with a remote query server over HTTP. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge to external, potentially untrusted codebases. It fetches and processes code, documentation, and agent-generated summaries which could contain malicious instructions designed to subvert the agent's behavior.
- Ingestion points: Content is ingested via subcommands like
ccx search,ccx grep,ccx read-file, and the cited answers fromccx ask(referenced inSKILL.md). - Boundary markers: The skill documentation does not mention the use of specific delimiters or markers to distinguish between codebase content and agent instructions.
- Capability inventory: The skill provides the agent with read-only access to remote codebase structures and file contents via the
ccxCLI. - Sanitization: There is no evidence of sanitization, filtering, or escaping of the ingested codebase content before it is processed by the agent.
Audit Metadata