codependix-navigate
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to run the
codependixCLI tool to perform dependency analysis and manage graph artifacts. These are standard operations for a developer tool. - [INDIRECT_PROMPT_INJECTION]: The skill parses dependency diagrams from
README.mdfiles, creating a potential surface for indirect prompt injection if those files contain malicious instructions. - Ingestion points:
README.mdfiles throughout the monorepo. - Boundary markers: The skill uses
<!-- codependix:start name=\"...\" -->markers to identify relevant data blocks. - Capability inventory: The skill is capable of executing shell commands via the
codependixCLI and reading workspace files. - Sanitization: No explicit sanitization or validation of the content found within the
README.mdmarkers is described.
Audit Metadata