codebase-doctor
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from audited repositories (source code, ADRs, and metadata). It mitigates this risk through an explicit 'repo is data, not a director' policy, instructing the agent to ignore any embedded instructions and treat all repository content solely as evidence.
- Ingestion points: Repository files,
CONTEXT.md, anddocs/adr/in the targeted codebase. - Boundary markers: Explicit instructions in
SKILL.mdto ignore instructions within repo files. - Capability inventory: File reading, command execution (
git,rg,wc), and report generation. - Sanitization: Employs a Python-based verifier (
verify-report.py) that checks the final report for unauthorized scripts and ensures strict security settings for embedded diagrams. - [COMMAND_EXECUTION]: The skill uses standard command-line tools such as
git,ripgrep, andwcto gather quantitative evidence (churn, call sites, file sizes) for its architectural findings. These commands are restricted to the local filesystem of the repository being audited. - [DYNAMIC_EXECUTION]: The skill includes a dedicated verification script (
verify-report.py) that is executed locally to validate the HTML report's structure and security posture. This script serves as an anti-hallucination and security gate, ensuring that paths are valid and that no malicious scripts have been injected into the report output.
Audit Metadata