legacy-modernizer
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to analyze and process existing legacy codebases which may contain malicious instructions.
- Ingestion points: Analyzes legacy codebases, service boundaries, and dependencies (File: SKILL.md, Step 1).
- Boundary markers: Absent; there are no instructions for the agent to distinguish between its own system prompts and instructions that might be embedded in the code it is modernizing.
- Capability inventory: The agent generates Python code (facades, feature flags, tests) and creates migration roadmaps based on its analysis.
- Sanitization: Absent; the skill does not specify any filtering or validation for content read from the target legacy systems.
Audit Metadata