ingest-code

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Uses subprocess to call local skill runners such as memory/run.sh for storing data and treesitter/run.sh for advanced parsing.
  • [EXTERNAL_DOWNLOADS]: Implements a fallback to install the standard typer library from PyPI if it is not present in the execution environment.
  • [DATA_EXFILTRATION]: Communicates with a local memory service at 127.0.0.1:8601; no network operations target external attacker-controlled domains.
  • [REMOTE_CODE_EXECUTION]: Dynamically loads the taxonomy module from defined local paths to enable security pattern matching.
  • [PROMPT_INJECTION]: The skill processes external codebase content but uses structural parsing (AST) and does not interpret data as high-privilege instructions, limiting the surface for indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ingest-code