monitor-codebase
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Extensive use of shell commands and subprocesses to coordinate complex workflows across multiple projects.\n
- Evidence: The
run.shscript executesfind,grep, and coordinates several other skills (project-state,cleanup,ingest-code, etc.) via their respective entry points.\n - Evidence:
autofix_docstrings.pyusessubprocess.runto calltreesitterandscillmfor analysis and docstring generation.\n- [COMMAND_EXECUTION]: Employs inline Python scripts for configuration parsing and data manipulation.\n - Evidence:
run.shusespython3 -cto parse~/.agent-inbox/projects.jsonand project-specific.monitor-codebase.jsonfiles.\n- [PROMPT_INJECTION]: Potential surface for indirect prompt injection from untrusted source code being analyzed.\n - Ingestion points: The skill reads local project source code (
.py,.tsx, etc.) and configuration files.\n - Boundary markers: Employs JSON formatting for violation data in generated task files for dispatched agents.\n
- Capability inventory: The skill can modify local source files, execute external scripts, and register scheduled tasks.\n
- Sanitization: Includes truncation of content sent to language models and stripping of formatting characters from model responses in
autofix_docstrings.py.
Audit Metadata