codependix-export
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of documentation for a legitimate dependency analysis tool named 'codependix'. It describes command-line arguments and configuration options for generating architectural reports. No malicious code, obfuscation, or persistence mechanisms were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill involves processing external workspace data which presents a potential surface for indirect prompt injection.\n
- Ingestion points: The tool reads
codependix.config.ts, source code (TypeScript, Python), and optionally external JSON project graphs.\n - Boundary markers: Output Mermaid diagrams are wrapped in HTML comment blocks (e.g.,
<!-- codependix:start ... -->).\n - Capability inventory: The tool performs file system analysis and writes report files (Markdown, JSON).\n
- Sanitization: Node identifiers in generated diagrams are sanitized from names and paths to prevent malformed diagram syntax.
Audit Metadata