improve-codebase-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data and interpolates it into a generated HTML report, creating a surface for indirect prompt injection.\n
- Ingestion points: The skill reads
git log --oneline,CONTEXT.md, and architectural decision records (ADRs) indocs/adr/, and uses a subagent to explore general codebase files (SKILL.md).\n - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are specified for the report generation process.\n
- Capability inventory: The skill writes a file to the OS temp directory and executes shell commands (
xdg-open,open,start) to launch the user's web browser (SKILL.md).\n - Sanitization: No sanitization or escaping of external content is defined. The report scaffold uses
securityLevel: 'loose'for the Mermaid diagramming library, which allows HTML rendering and increases the risk of cross-site scripting (XSS) if malicious content is found in the scanned files (HTML-REPORT.md).\n- [EXTERNAL_DOWNLOADS]: The generated HTML report fetches external assets from well-known services at runtime.\n - Evidence: The report scaffold in
HTML-REPORT.mdreferences Tailwind CSS (cdn.tailwindcss.com) and the Mermaid library (cdn.jsdelivr.net) via CDN links.\n- [COMMAND_EXECUTION]: The skill utilizes standard shell commands to analyze the codebase and present results.\n - Evidence:
SKILL.mdusesgit logto identify file hot spots and platform-specific commands likexdg-openorstartto display the generated HTML report.
Audit Metadata