codebase-documenter

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze arbitrary codebase content through tools like Glob, Grep, Read, and the Explore agent. This creates a surface for indirect prompt injection if the target code contains maliciously crafted instructions (e.g., in comments or documentation blocks) intended to influence the agent's behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses significant capabilities, including Bash for metadata extraction and Write for document creation, which could be misused if an injection attack is successful.
  • [INDIRECT_PROMPT_INJECTION]: There are no explicit boundary markers or instructions within the skill to treat codebase content as potentially untrusted data or to ignore embedded instructions found during analysis.
  • [INDIRECT_PROMPT_INJECTION]: The Explore agent approach increases the depth of ingestion, potentially exposing the agent to more hidden injection points throughout the codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:23 AM
Security Audit — agent-trust-hub — codebase-documenter