search-tools
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions provide guidance on using command-line tools like 'leann', 'ast-grep', and 'morph' for code analysis and search. These tools are described as being used for legitimate development tasks like semantic search and structural code analysis.
- [INDIRECT_PROMPT_INJECTION]: As the skill involves tools that read and process codebase content, it possesses an attack surface for indirect prompt injection if the files being searched contain malicious instructions designed to manipulate the agent's behavior. Ingestion points: Codebase search results. Boundary markers: Not defined in instructions. Capability inventory: Execution of CLI search tools. Sanitization: None mentioned.
Audit Metadata