codebase-diagram
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run local Python scripts (
inject.pyandscan.py) for data injection and security validation.\n- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill references an externalhere-nowskill to provide optional publishing capabilities, relying on its script for remote delivery.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses repository source code to build visualizations. It enforces data protection by requiring a secret scan and following strict privacy rules to exclude credentials and personal information.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted repository content. Ingestion points include README and source files. The skill mitigates risks using explicit instructional boundaries and a mandatory post-generation scan (scan.py) to detect and block sensitive content before delivery.
Audit Metadata