code-analyzer

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The file scripts/main.cjs executes a Node.js script (analyzer.mjs) located at a path computed at runtime by searching upward for a .claude folder in the directory hierarchy.
  • [COMMAND_EXECUTION]: The script scripts/main.cjs uses child_process.spawn to execute a local process and passes command-line arguments (process.argv) directly into the spawned child process.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted project source code, the results of which are returned to the agent's context, potentially allowing malicious content (such as hidden instructions in code comments) in analyzed files to influence agent behavior.
  • Ingestion points: Project files are read using the Read, Grep, and Glob tools, as well as the project-wide scan performed by the script referenced in scripts/main.cjs.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the prompt instructions for handling analysis output.
  • Capability inventory: The skill possesses the ability to spawn subprocesses via child_process.spawn in scripts/main.cjs and utilizes system tools like Bash.
  • Sanitization: The skill does not implement sanitization or filtering of the source code content before processing it for metrics or returning summaries to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 07:56 AM
Security Audit — agent-trust-hub — code-analyzer