monitor-codebase

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Extensive use of shell commands and subprocesses to coordinate complex workflows across multiple projects.\n
  • Evidence: The run.sh script executes find, grep, and coordinates several other skills (project-state, cleanup, ingest-code, etc.) via their respective entry points.\n
  • Evidence: autofix_docstrings.py uses subprocess.run to call treesitter and scillm for analysis and docstring generation.\n- [COMMAND_EXECUTION]: Employs inline Python scripts for configuration parsing and data manipulation.\n
  • Evidence: run.sh uses python3 -c to parse ~/.agent-inbox/projects.json and project-specific .monitor-codebase.json files.\n- [PROMPT_INJECTION]: Potential surface for indirect prompt injection from untrusted source code being analyzed.\n
  • Ingestion points: The skill reads local project source code (.py, .tsx, etc.) and configuration files.\n
  • Boundary markers: Employs JSON formatting for violation data in generated task files for dispatched agents.\n
  • Capability inventory: The skill can modify local source files, execute external scripts, and register scheduled tasks.\n
  • Sanitization: Includes truncation of content sent to language models and stripping of formatting characters from model responses in autofix_docstrings.py.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — monitor-codebase