codebase-intelligence
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown instructions and metadata. No executable scripts, binaries, or configuration files are included.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted codebase data, which presents an attack surface for indirect prompt injection. 1. Ingestion points: The skill instructs the agent to read and search repository files, configuration files, and generated artifacts during the mapping and impact scan phases. 2. Boundary markers: The skill does not define specific delimiters or instructions to ignore content within the analyzed files. 3. Capability inventory: The agent uses file system read and search tools to perform audits. 4. Sanitization: No explicit sanitization or filtering of analyzed content is mentioned.
Audit Metadata