skills/idaibin/skills/repo-map/Gen Agent Trust Hub

repo-map

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from potentially untrusted external sources, specifically the repository being scanned.\n- Ingestion points: The skill reads repository source code, manifests (e.g., package.json, pom.xml), configuration files, and tests via the repository.asset.scan capability.\n- Boundary markers: The instructions include explicit 'Hard Rules' that prohibit copying the full bodies of files into the asset graph, focusing instead on stable identity and relationships.\n- Capability inventory: The skill defines itself as read-only for repository source and Git, limiting its output to a local store or derived navigation views.\n- Sanitization: The agent is instructed to record only metadata such as hashes, locators, and authority roles, which prevents the agent from interpreting and acting upon malicious instructions embedded within the source code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 05:39 AM
Security Audit — agent-trust-hub — repo-map