codekb-search
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious code, obfuscation, or direct injection patterns were detected. The skill is limited to defining search logic for an MCP tool.- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection due to its core function of retrieving and processing external codebase content.1. Ingestion points: Data retrieved via the
codekb_searchtool, including code chunks and knowledge entries (referenced in SKILL.md).2. Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are defined.3. Capability inventory: The skill utilizescodekb_search,codegraph explore,rg, andgrep.4. Sanitization: No content sanitization or validation logic is implemented.
Audit Metadata