fossil
Pass
Audited by Gen Agent Trust Hub on May 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily a documentation and analysis tool. It includes explicit 'Never' constraints against modifying production environments or tests, ensuring it remains a passive observer of the system.
- [DATA_EXPOSURE]: By design, the skill must read sensitive internal data including source code, database schemas, git history, and infrastructure configurations to perform its analysis. This behavior is consistent with its stated purpose of legacy system excavation.
- [INDIRECT_PROMPT_INJECTION]: The skill has a large attack surface as it ingests and processes legacy code and developer comments which may contain untrusted content. However, it implements robust mitigation strategies by requiring multi-source corroboration (cross-referencing code, tests, and history) and explicitly labeling speculative findings to ensure the agent does not treat embedded logic as authoritative instructions.
Audit Metadata