codebase-onboarding

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's instructions are focused on passive analysis of repository metadata and structure. It does not attempt to execute commands, access sensitive system files (like SSH keys), or bypass safety filters. Findings are consistent with standard developer productivity tools.- [PROMPT_INJECTION]: The skill processes untrusted codebase data, which is an inherent surface for indirect prompt injection. However, given its purpose as a documentation tool, the risk is assessed as safe within its functional context.
  • Ingestion points: The agent reads project manifests (e.g., package.json, go.mod), configuration files, and source code during the reconnaissance phase.
  • Boundary markers: The instructions do not explicitly define delimiters for external content, but the agent is directed to perform specific, structured extraction tasks which limits the impact of embedded instructions.
  • Capability inventory: The agent uses file reading tools, directory listing, and the ability to write a Markdown-based configuration file (CLAUDE.md).
  • Sanitization: Content is summarized into structured documentation rather than being used to drive dynamic execution, which significantly mitigates the risk of obedience to injected instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:21 AM
Security Audit — agent-trust-hub — codebase-onboarding