codependix-triage
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides technical guidance for using the codependix architectural tool. No malicious logic, obfuscation, or sensitive data exposure was found.
- [NO_CODE]: The skill is strictly instructional and does not bundle any executable code or scripts.
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process outputs from the codependix CLI and modify configuration files. 1. Ingestion points: The agent reads codependix exit codes and terminal output in SKILL.md. 2. Boundary markers: No specific delimiters are defined for tool output. 3. Capability inventory: The agent is authorized to execute codependix commands and perform file-system modifications to codependix.config.ts and project readmes. 4. Sanitization: No explicit sanitization of tool output is described. Given the tool's role in local architectural analysis, this surface is considered low risk.
Audit Metadata