scan
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local shell commands, including
rg(ripgrep) for text discovery and a Python-based utility located at.claude/scripts/code_graphfor tracing code dependencies and call chains. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) as it reads and processes untrusted data from the repository being scanned without applying boundary markers or sanitization to separate data from instructions.
- Ingestion points: The scanner reads source code, markdown documentation, and configuration files throughout the project directory (e.g.,
src/,docs/specs/). - Boundary markers: The protocol lacks explicit delimiters or instructions to the AI to ignore embedded commands within the files it reads during Phase 2 (Execute Scan).
- Capability inventory: The skill allows shell command execution (
rg), file system writes to thedocs/andplans/directories, and the ability to spawn sub-agents (spawn_agent). - Sanitization: There is no evidence of escaping or filtering logic applied to content extracted from project files before it is passed to the AI for summarization.
- [SAFE]: The skill contains significant positive security controls, specifically blocking the collection of secret values (passwords, tokens, and keys) during its environment and infrastructure scans, opting instead to record only the names and mechanisms of secret management.
Audit Metadata