research-codebase

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves a clear, productive purpose of documenting existing code structures and flows. It includes robust instructions to maintain objectivity and provides file-level references for its findings.
  • [PROMPT_INJECTION]: The skill's architecture involves ingesting user-provided research questions which are then used to direct sub-agents. This surface is managed through specific scoping instructions.
  • Ingestion points: Research questions supplied via file paths or inline text as defined in SKILL.md.
  • Boundary markers: Instructions explicitly constrain sub-agents to only their specific questions and mandate the exclusion of opinions or suggestions.
  • Capability inventory: The skill utilizes file reading, sub-agent spawning for context-specific tasks, and file writing to the local working directory.
  • Sanitization: The skill relies on strict instructional constraints and template-based output to ensure data is processed objectively without sanitization of the input text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 10:17 AM
Security Audit — agent-trust-hub — research-codebase