codebase-advisor
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes defensive instructions to specifically ignore and report any 'ignore previous instructions' or similar injection patterns encountered within the files being audited. While detected by static analysis, these are safety guardrails rather than malicious injections.
- [DATA_EXFILTRATION]: The skill implements strict credential hygiene. It is instructed to never reproduce secret values (API keys, tokens) in findings or plans, referencing only the file location and credential type. Additionally, it requires user confirmation before publishing any sensitive findings to public GitHub issues via the
ghtool. - [COMMAND_EXECUTION]: The skill uses various shell commands for auditing (e.g.,
git log,npm audit,tsc --noEmit). These are scoped and primarily read-only. Modification of the codebase is delegated to a separate executor subagent running in an isolated git worktree, ensuring the primary advisor agent never mutates the user's working directory. - [INDIRECT_PROMPT_INJECTION]: As a tool that surveys untrusted codebases, it has a natural attack surface for indirect prompt injection. The skill mitigates this by mandating that all content read from the repository be treated as data, not instructions, and by requiring that subagents inherit these same safety rules.
- [REMOTE_CODE_EXECUTION]: The skill can dispatch subagents to execute implementation plans. This is a core feature for automated refactoring. Security is managed by running these subagents in isolated environments (worktrees) and requiring the advisor to review the resulting diffs like a technical lead.
Audit Metadata