codependix-navigate

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to run the codependix CLI tool to perform dependency analysis and manage graph artifacts. These are standard operations for a developer tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses dependency diagrams from README.md files, creating a potential surface for indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: README.md files throughout the monorepo.
  • Boundary markers: The skill uses <!-- codependix:start name=\"...\" --> markers to identify relevant data blocks.
  • Capability inventory: The skill is capable of executing shell commands via the codependix CLI and reading workspace files.
  • Sanitization: No explicit sanitization or validation of the content found within the README.md markers is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:18 PM
Security Audit — agent-trust-hub — codependix-navigate