codealive-context-engine

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the subprocess module in setup.py and api_client.py to interact with platform-specific credential managers such as the macOS Keychain, Windows Credential Manager, and Linux secret-tool. These operations are restricted to hardcoded service labels and are used exclusively for secure API key management, representing standard administrative behavior for a vendor-provided tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it ingests and processes external code and documentation through tools like fetch.py, search.py, and grep.py. Evidence chain: 1) Ingestion points include scripts that fetch content from remote repositories; 2) Boundary markers are provided in SKILL.md, which instructs the agent to use specific triage workflows and treat actual code content as the source of truth; 3) Capability inventory consists of network requests to the CodeAlive API and file read access; 4) No explicit sanitization is performed on ingested code strings by the scripts, meaning the agent must rely on its own context-parsing safeguards.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 08:26 AM
Security Audit — agent-trust-hub — codealive-context-engine