code-semantic-search
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/main.cjsconstructs the path to its CLI tool (.claude/tools/cli/hybrid-search.cjs) at runtime by searching for a project root marker, then executes it using the Node.js runtime. - [COMMAND_EXECUTION]: The skill uses
child_process.spawninscripts/main.cjsto launch the externalhybrid-search.cjstool with arguments derived from skill input. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its core function of indexing and searching project source code.
- Ingestion points: The skill reads and processes source code files from the local filesystem during search operations.
- Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from following potential instructions embedded within the code results.
- Capability inventory: The skill has the capability to execute sub-processes (
spawninscripts/main.cjs) and is instructed to write to memory files in the.claude/context/memory/directory. - Sanitization: There is no evidence of content sanitization or validation performed on the files being indexed or the search results returned to the agent context.
Audit Metadata