code-necromancer
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides utility scripts (scripts/analyze-repo.sh, scripts/scan-repos.sh) and guides the agent to use command-line tools such as gh, jq, npm audit, and various cloud provider CLIs to map repository structures and infrastructure resources. These are standard operations for the skill's intended purpose of codebase modernization.
- [INDIRECT_PROMPT_INJECTION]: The archaeology workflow involves reading and analyzing arbitrary content from external repositories. Maliciously crafted data within these repositories (e.g., in README files or code comments) could attempt to influence the agent's behavior. The skill does not explicitly define sanitization steps or boundary markers for the data ingested during analysis.
Audit Metadata