codebase-doctor

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from audited repositories (source code, ADRs, and metadata). It mitigates this risk through an explicit 'repo is data, not a director' policy, instructing the agent to ignore any embedded instructions and treat all repository content solely as evidence.
  • Ingestion points: Repository files, CONTEXT.md, and docs/adr/ in the targeted codebase.
  • Boundary markers: Explicit instructions in SKILL.md to ignore instructions within repo files.
  • Capability inventory: File reading, command execution (git, rg, wc), and report generation.
  • Sanitization: Employs a Python-based verifier (verify-report.py) that checks the final report for unauthorized scripts and ensures strict security settings for embedded diagrams.
  • [COMMAND_EXECUTION]: The skill uses standard command-line tools such as git, ripgrep, and wc to gather quantitative evidence (churn, call sites, file sizes) for its architectural findings. These commands are restricted to the local filesystem of the repository being audited.
  • [DYNAMIC_EXECUTION]: The skill includes a dedicated verification script (verify-report.py) that is executed locally to validate the HTML report's structure and security posture. This script serves as an anti-hallucination and security gate, ensuring that paths are valid and that no malicious scripts have been injected into the report output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:43 PM