codependix-export

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of documentation for a legitimate dependency analysis tool named 'codependix'. It describes command-line arguments and configuration options for generating architectural reports. No malicious code, obfuscation, or persistence mechanisms were identified.\n- [INDIRECT_PROMPT_INJECTION]: The skill involves processing external workspace data which presents a potential surface for indirect prompt injection.\n
  • Ingestion points: The tool reads codependix.config.ts, source code (TypeScript, Python), and optionally external JSON project graphs.\n
  • Boundary markers: Output Mermaid diagrams are wrapped in HTML comment blocks (e.g., <!-- codependix:start ... -->).\n
  • Capability inventory: The tool performs file system analysis and writes report files (Markdown, JSON).\n
  • Sanitization: Node identifiers in generated diagrams are sanitized from names and paths to prevent malformed diagram syntax.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:18 PM
Security Audit — agent-trust-hub — codependix-export