learn
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs localized operations intended for project onboarding and architecture understanding.
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests untrusted data from the codebase's source files (Ingestion points: 8-20 source files as defined in SKILL.md). However, the agent's capabilities are restricted to generating and updating local markdown documentation (Capability inventory: Updates architecture.md, request-flow.md, important-files.md, and progress.md). No boundary markers or sanitization routines are implemented to filter instructions potentially embedded in source code.
- [DATA_EXFILTRATION]: Accesses internal project state files and documentation (e.g., docs/onboarding/project-memory.md). There is no access to sensitive system paths or credentials, and no network operations are present to facilitate data exfiltration.
Audit Metadata