archaeologist
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructs the agent to adopt a specific persona ('archaeologist') to help explain code history and surface technical debt. The behavior is purely instructional and does not introduce malicious logic.
- [EXTERNAL_DOWNLOADS]: The instructions suggest installing the 'repowise' Python package and visit 'repowise.dev'. These resources belong to the skill author ('repowise-dev') and are presented as optional enhancements for the skill's functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from the codebase, such as git logs, blame information, and documentation (ADRs, CHANGELOGs). While these are ingestion points for untrusted data, the risk is inherent to the task of code analysis, and no specific exploitable patterns were found.
Audit Metadata