inno-code-survey

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses a helper script (scripts/github_search_clone.py) to query the GitHub Search API and clone repositories based on user-defined research topics. Although GitHub is a well-known service, the skill downloads arbitrary code from third-party sources at runtime.
  • [COMMAND_EXECUTION]: The skill executes shell commands, including git clone via subprocess.run and various Linux utilities (ls, tree, find, grep), to manage and navigate the local workspace during repository analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by reading and summarizing the contents of externally sourced repositories. Malicious instructions embedded in a repository's documentation or source code could potentially influence the agent's behavior during Phase B (Code Survey).
  • Ingestion points: Contents of cloned repositories (e.g., README.md, Python files) in Experiment/code_references/ and GitHub API response data.
  • Boundary markers: The prompt templates in prompts/build_code_survey_query.md and instructions in references/code_survey_agent.md do not include explicit delimiters or instructions to ignore commands found within analyzed data.
  • Capability inventory: The agent has access to file operations and terminal execution capabilities, which could be misused if instructions from untrusted sources are inadvertently followed.
  • Sanitization: No sanitization or validation mechanisms are implemented for the content read from external repositories before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 PM