analyze-codebase-for-mcp
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it processes untrusted data from external codebases.
- Ingestion points: The skill uses
Read,Grep, andGlobtools to ingest content from arbitrary source code and configuration files (e.g.,package.json,setup.py) specified by the user in Step 1 and Step 2. - Boundary markers: There are no protective boundary markers or instructions telling the agent to ignore potentially malicious natural language instructions embedded within comments or documentation of the analyzed codebase.
- Capability inventory: The skill is granted
Bash,Read,Grep, andGlobcapabilities, allowing it to perform file system operations and command execution based on its findings. - Sanitization: No sanitization, escaping, or validation of the ingested code content is performed before the agent processes it for analysis.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to perform project metrics. - Evidence: Step 1.3 instructs the agent to use
Bashto calculate the total number of files and lines of code. While this specific application is aligned with the skill's primary purpose, it leverages a high-privilege tool on the local environment.
Audit Metadata