codebase-audit
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to read all source files in a target directory (default
mcp/src/) using thecode-explorersubagent to perform an audit. This creates a significant attack surface where malicious instructions embedded in the audited source code could influence the agent's behavior during issue creation, PR submission, or code fixing phases. - Ingestion points: The audit process in
SKILL.md(Phase 1, Step 2) andreferences/review-strategy.mdreads every source file in the repository. - Boundary markers: No specific delimiters or instructions to ignore embedded prompts are defined for the reading subagent.
- Capability inventory: The skill has capabilities to create GitHub issues (
gh issue create), create pull requests (gh pr create), and push code to remote repositories (git push). - Sanitization: There is no evidence of sanitization or filtering of the content read from files before it is used to generate issue bodies or PR descriptions.
- [COMMAND_EXECUTION]: The skill automates the execution of local development commands on the codebase being audited.
- Evidence: In
references/worktree-fix.md(Step 2 and Step 4), the skill is instructed to runnpm ci,npm run build, andnpm run testwithin a git worktree. - Risk: If the repository under audit contains malicious code (e.g., in
package.jsonscripts or test files), these commands will trigger local code execution on the environment where the agent is running.
Audit Metadata