codependix-triage

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides technical guidance for using the codependix architectural tool. No malicious logic, obfuscation, or sensitive data exposure was found.
  • [NO_CODE]: The skill is strictly instructional and does not bundle any executable code or scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process outputs from the codependix CLI and modify configuration files. 1. Ingestion points: The agent reads codependix exit codes and terminal output in SKILL.md. 2. Boundary markers: No specific delimiters are defined for tool output. 3. Capability inventory: The agent is authorized to execute codependix commands and perform file-system modifications to codependix.config.ts and project readmes. 4. Sanitization: No explicit sanitization of tool output is described. Given the tool's role in local architectural analysis, this surface is considered low risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:18 PM
Security Audit — agent-trust-hub — codependix-triage