ingest-code
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Uses subprocess to call local skill runners such as
memory/run.shfor storing data andtreesitter/run.shfor advanced parsing. - [EXTERNAL_DOWNLOADS]: Implements a fallback to install the standard
typerlibrary from PyPI if it is not present in the execution environment. - [DATA_EXFILTRATION]: Communicates with a local memory service at
127.0.0.1:8601; no network operations target external attacker-controlled domains. - [REMOTE_CODE_EXECUTION]: Dynamically loads the
taxonomymodule from defined local paths to enable security pattern matching. - [PROMPT_INJECTION]: The skill processes external codebase content but uses structural parsing (AST) and does not interpret data as high-privilege instructions, limiting the surface for indirect prompt injection.
Audit Metadata