map-dependencies
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill contains no executable scripts or commands. It functions as a set of logical instructions for the AI agent to follow when analyzing a codebase.
- [INDIRECT_PROMPT_INJECTION]: The skill involves reading and analyzing project source files, which represents a surface for indirect prompt injection. However, since the agent is instructed to perform static structural mapping (identifying import statements) rather than executing or interpreting the code's logic, the risk is minimal.
- Ingestion points: Project source files (JS/TS, Python, Go, etc.) read via agent tools.
- Boundary markers: None explicitly defined in the prompt instructions.
- Capability inventory: Uses file reading and search (grep) capabilities to identify dependency relationships.
- Sanitization: None specified for the processed content.
- [COMMAND_EXECUTION]: While the skill mentions using
grep, it is presented as a procedural step for the agent to use its existing tools rather than a direct shell command to be executed without oversight.
Audit Metadata