zoom-out
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
subprocessmodule in Python to executegitfor repository discovery and to run its own internal scripts for inventory and validation. These commands are localized to the repository being analyzed and are essential for generating the requested architecture maps. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests and processes untrusted code from the local repository.
- Ingestion points: The
scripts/zoom_out_inventory.pyscript reads the content of repository files to identify symbols, imports, and caller relationships. - Boundary markers: The skill includes an
output-contract.mdthat defines evidence labels such as 'Verified', 'Likely', and 'Lead' to help the agent categorize the reliability of the information it finds. - Capability inventory: The skill possesses the ability to read arbitrary files within the repository and execute
gitvia subprocess. - Sanitization: The skill performs heuristic scanning of repository content but does not implement explicit content sanitization.
- [DATA_EXFILTRATION]: The
zoom_out_inventory.pyscript is configured to recognize.envfiles as relevant configuration files to search for symbols. While this enables the agent to read potentially sensitive configuration data, there are no network operations or external endpoints present in the skill to facilitate data exfiltration.
Audit Metadata