inno-code-survey
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a helper script (
scripts/github_search_clone.py) to query the GitHub Search API and clone repositories based on user-defined research topics. Although GitHub is a well-known service, the skill downloads arbitrary code from third-party sources at runtime. - [COMMAND_EXECUTION]: The skill executes shell commands, including
git cloneviasubprocess.runand various Linux utilities (ls,tree,find,grep), to manage and navigate the local workspace during repository analysis. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by reading and summarizing the contents of externally sourced repositories. Malicious instructions embedded in a repository's documentation or source code could potentially influence the agent's behavior during Phase B (Code Survey).
- Ingestion points: Contents of cloned repositories (e.g.,
README.md, Python files) inExperiment/code_references/and GitHub API response data. - Boundary markers: The prompt templates in
prompts/build_code_survey_query.mdand instructions inreferences/code_survey_agent.mddo not include explicit delimiters or instructions to ignore commands found within analyzed data. - Capability inventory: The agent has access to file operations and terminal execution capabilities, which could be misused if instructions from untrusted sources are inadvertently followed.
- Sanitization: No sanitization or validation mechanisms are implemented for the content read from external repositories before it is processed by the agent.
Audit Metadata