unearth-specification
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted codebase data, which is an inherent vector for indirect prompt injection via malicious comments or documentation within the analyzed system.
- Ingestion points: The skill reads project manifests (Setup Step 3), performs dependency graph analysis (Phase 1), and extracts logic/schema from source code (Phase 2).
- Boundary markers: Employs a dedicated 'Assayer' (Skeptic) agent to challenge all deliverables for accuracy and completeness before advancing phases.
- Capability inventory: Orchestrates sub-agents using
TeamCreateandAgenttools; writes documentation artifacts to the localdocs/directory. - Sanitization: Includes a non-negotiable principle (Rule 4) forbidding secrets in context, though it does not explicitly describe sanitization of instruction-like content in code comments.
- [CREDENTIALS_UNSAFE]: The skill includes high-value security principles, specifically Rule 4 ('No secrets in context'), which prohibits agents from including API keys, tokens, or PII in prompts, messages, or checkpoint files. It instructs agents to flag discovered secrets by file path/line number rather than value.
Audit Metadata