unearth-specification

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted codebase data, which is an inherent vector for indirect prompt injection via malicious comments or documentation within the analyzed system.
  • Ingestion points: The skill reads project manifests (Setup Step 3), performs dependency graph analysis (Phase 1), and extracts logic/schema from source code (Phase 2).
  • Boundary markers: Employs a dedicated 'Assayer' (Skeptic) agent to challenge all deliverables for accuracy and completeness before advancing phases.
  • Capability inventory: Orchestrates sub-agents using TeamCreate and Agent tools; writes documentation artifacts to the local docs/ directory.
  • Sanitization: Includes a non-negotiable principle (Rule 4) forbidding secrets in context, though it does not explicitly describe sanitization of instruction-like content in code comments.
  • [CREDENTIALS_UNSAFE]: The skill includes high-value security principles, specifically Rule 4 ('No secrets in context'), which prohibits agents from including API keys, tokens, or PII in prompts, messages, or checkpoint files. It instructs agents to flag discovered secrets by file path/line number rather than value.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 02:02 PM