analyze-codebase-for-mcp

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it processes untrusted data from external codebases.
  • Ingestion points: The skill uses Read, Grep, and Glob tools to ingest content from arbitrary source code and configuration files (e.g., package.json, setup.py) specified by the user in Step 1 and Step 2.
  • Boundary markers: There are no protective boundary markers or instructions telling the agent to ignore potentially malicious natural language instructions embedded within comments or documentation of the analyzed codebase.
  • Capability inventory: The skill is granted Bash, Read, Grep, and Glob capabilities, allowing it to perform file system operations and command execution based on its findings.
  • Sanitization: No sanitization, escaping, or validation of the ingested code content is performed before the agent processes it for analysis.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform project metrics.
  • Evidence: Step 1.3 instructs the agent to use Bash to calculate the total number of files and lines of code. While this specific application is aligned with the skill's primary purpose, it leverages a high-privilege tool on the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 12:14 PM
Security Audit — agent-trust-hub — analyze-codebase-for-mcp