ccc-makeover
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted data from external codebases, which could contain malicious instructions intended to manipulate the agent's behavior during audits or makeover operations.\n
- Ingestion points: Project codebase files scanned and processed by sub-skills (e.g., xray, makeover).\n
- Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to separate untrusted data from the agent's instructions.\n
- Capability inventory: The skill includes the capability to automatically apply fixes (makeover) and execute other skills, allowing for potential file system modification or unauthorized actions if an injection occurs.\n
- Sanitization: No input validation or sanitization mechanisms for content read from the project files are mentioned in the skill documentation.\n- [NO_CODE]: The skill defines an orchestration workflow and describes complex multi-step logic but does not include any accompanying executable code, scripts, or binary files, relying instead on referenced sub-skills that are expected to be available in the environment.
Audit Metadata