codebase-documenter
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze arbitrary codebase content through tools like
Glob,Grep,Read, and theExploreagent. This creates a surface for indirect prompt injection if the target code contains maliciously crafted instructions (e.g., in comments or documentation blocks) intended to influence the agent's behavior. - [INDIRECT_PROMPT_INJECTION]: The skill possesses significant capabilities, including
Bashfor metadata extraction andWritefor document creation, which could be misused if an injection attack is successful. - [INDIRECT_PROMPT_INJECTION]: There are no explicit boundary markers or instructions within the skill to treat codebase content as potentially untrusted data or to ignore embedded instructions found during analysis.
- [INDIRECT_PROMPT_INJECTION]: The
Exploreagent approach increases the depth of ingestion, potentially exposing the agent to more hidden injection points throughout the codebase.
Audit Metadata