improve-codebase-architecture
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches resources from well-known content delivery networks to render its architectural reports.
- Evidence: Loads the Tailwind CSS library from
https://cdn.tailwindcss.cominHTML-REPORT.md. - Evidence: Downloads the Mermaid diagramming tool from
https://cdn.jsdelivr.net/npm/mermaid@11/dist/mermaid.esm.min.mjsinHTML-REPORT.md. - [COMMAND_EXECUTION]: The skill uses system shell commands to perform codebase analysis and display the final report to the user.
- Evidence: Executes
git log --onelineinSKILL.mdto identify frequently changed files and hotspots. - Evidence: Utilizes platform-specific commands
xdg-open,open, orstartinSKILL.mdto automatically launch the generated HTML report in the user's default browser. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the codebase being scanned, which is then interpolated into a generated HTML file that the user is encouraged to open.
- Ingestion points: The skill reads file names, codebase structures,
git logoutput,CONTEXT.mdfiles, and Architecture Decision Records (ADRs) as specified inSKILL.md. - Boundary markers: The instructions do not specify the use of strict delimiters or sanitization routines when including this external data in the HTML report.
- Capability inventory: The skill has the capability to write to the system temporary directory and invoke system commands to open generated files (
SKILL.md). - Sanitization: There is no explicit requirement for the agent to escape or validate data retrieved from the codebase before including it in the report cards or diagrams.
Audit Metadata