codebase-intelligence

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown instructions and metadata. No executable scripts, binaries, or configuration files are included.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted codebase data, which presents an attack surface for indirect prompt injection. 1. Ingestion points: The skill instructs the agent to read and search repository files, configuration files, and generated artifacts during the mapping and impact scan phases. 2. Boundary markers: The skill does not define specific delimiters or instructions to ignore content within the analyzed files. 3. Capability inventory: The agent uses file system read and search tools to perform audits. 4. Sanitization: No explicit sanitization or filtering of analyzed content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:51 AM
Security Audit — agent-trust-hub — codebase-intelligence