codebase-audit

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read all source files in a target directory (default mcp/src/) using the code-explorer subagent to perform an audit. This creates a significant attack surface where malicious instructions embedded in the audited source code could influence the agent's behavior during issue creation, PR submission, or code fixing phases.
  • Ingestion points: The audit process in SKILL.md (Phase 1, Step 2) and references/review-strategy.md reads every source file in the repository.
  • Boundary markers: No specific delimiters or instructions to ignore embedded prompts are defined for the reading subagent.
  • Capability inventory: The skill has capabilities to create GitHub issues (gh issue create), create pull requests (gh pr create), and push code to remote repositories (git push).
  • Sanitization: There is no evidence of sanitization or filtering of the content read from files before it is used to generate issue bodies or PR descriptions.
  • [COMMAND_EXECUTION]: The skill automates the execution of local development commands on the codebase being audited.
  • Evidence: In references/worktree-fix.md (Step 2 and Step 4), the skill is instructed to run npm ci, npm run build, and npm run test within a git worktree.
  • Risk: If the repository under audit contains malicious code (e.g., in package.json scripts or test files), these commands will trigger local code execution on the environment where the agent is running.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 09:31 AM
Security Audit — agent-trust-hub — codebase-audit