codependix-configure
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [SAFE]: The skill consists entirely of documentation and configuration examples for the codependix tool. No malicious code, unauthorized file access, or command execution patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a tool that processes potentially untrusted workspace data, which represents a known vulnerability surface if the tool's output is consumed by an LLM.
- Ingestion points: Project source files,
tsconfig.json, and an external JSON project graph path specified in theprojectGraphfield (SKILL.md). - Boundary markers: The configuration schema does not explicitly require or describe delimiters to separate data from instructions.
- Capability inventory: The skill itself contains no executable scripts; the tool it documents performs file writes (Markdown/JSON) and graph validation (SKILL.md).
- Sanitization: No input validation or data sanitization mechanisms are mentioned in the configuration guide.
- [DYNAMIC_EXECUTION]: The documentation mentions that codependix loads TypeScript and JavaScript configuration files from the project directory. While this involves dynamic loading, it is a standard and expected behavior for localized developer tools and does not constitute a security issue in the skill content.
Audit Metadata