code-semantic-search

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/main.cjs constructs the path to its CLI tool (.claude/tools/cli/hybrid-search.cjs) at runtime by searching for a project root marker, then executes it using the Node.js runtime.
  • [COMMAND_EXECUTION]: The skill uses child_process.spawn in scripts/main.cjs to launch the external hybrid-search.cjs tool with arguments derived from skill input.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection due to its core function of indexing and searching project source code.
  • Ingestion points: The skill reads and processes source code files from the local filesystem during search operations.
  • Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from following potential instructions embedded within the code results.
  • Capability inventory: The skill has the capability to execute sub-processes (spawn in scripts/main.cjs) and is instructed to write to memory files in the .claude/context/memory/ directory.
  • Sanitization: There is no evidence of content sanitization or validation performed on the files being indexed or the search results returned to the agent context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:40 PM
Security Audit — agent-trust-hub — code-semantic-search