legacy-archaeology
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to access and analyze sensitive file paths, specifically
.envfiles, to identify environment variables and database connection strings as part of its 'Survey Phase' and 'Dependency Mapping' processes (found inreferences/patterns.md). While this is intended for context gathering, it creates a surface for sensitive data exposure. - [COMMAND_EXECUTION]: The skill provides specific command-line templates for
git(e.g.,git shortlog,git log,git blame) to be used for history reconstruction and identifying code authorship (found inreferences/patterns.md). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data in the form of legacy codebases and their associated metadata.
- Ingestion points: The agent reads source code,
READMEfiles, deployment configurations, database schemas, and test files (references/patterns.md). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the analyzed code are provided.
- Capability inventory: The agent has the capability to read local files and potentially execute shell commands (
git) to perform its task. - Sanitization: No sanitization or validation of the ingested code content is mentioned.
Audit Metadata