legacy-modernizer

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to analyze and process existing legacy codebases which may contain malicious instructions.
  • Ingestion points: Analyzes legacy codebases, service boundaries, and dependencies (File: SKILL.md, Step 1).
  • Boundary markers: Absent; there are no instructions for the agent to distinguish between its own system prompts and instructions that might be embedded in the code it is modernizing.
  • Capability inventory: The agent generates Python code (facades, feature flags, tests) and creates migration roadmaps based on its analysis.
  • Sanitization: Absent; the skill does not specify any filtering or validation for content read from the target legacy systems.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:42 AM
Security Audit — agent-trust-hub — legacy-modernizer