ln-54-codebase-auditor
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data (source code, manifests, and documentation) from the repository being audited, which is a vector for indirect prompt injection.
- Ingestion points: The skill accesses repository content using native file listing, manifests, build files, and language servers as specified in the 'Tool Routing' section.
- Boundary markers: The instructions include a checklist to distinguish confirmed reachability and context from static suspicion, though they do not provide specific text-based delimiters for content interpolation.
- Capability inventory: The skill is authorized to run repository-defined build, lint, type, test, and smoke commands, as well as git operations and package audits.
- Sanitization: The instructions explicitly mandate the redaction of raw credential values and sensitive data in the audit report.
- [DYNAMIC_EXECUTION]: The skill executes repository-defined diagnostic commands (e.g., build scripts, test suites, and smoke tests) to verify delivery health. This constitutes execution of code found within the audited environment.
- [COMMAND_EXECUTION]: The agent is instructed to use various CLI tools including git, language servers, and package managers to perform its analysis.
Audit Metadata