cognee-code

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill indexes external codebases and provides extracted architectural facts to the agent's context under '=== Code graph facts ===' headers. This creates an indirect prompt injection surface where malicious content within a repository could attempt to influence the agent's behavior.
  • Ingestion points: External code repositories indexed via cognee-index-repo.sh in SKILL.md.
  • Boundary markers: Data injection is delimited by '=== Code graph facts ===' markers as specified in SKILL.md.
  • Capability inventory: The skill performs graph traversals, impact analysis, and neighborhood exploration via cognee-search.sh in SKILL.md.
  • Sanitization: No explicit content sanitization or validation of the indexed code files is mentioned.
  • [COMMAND_EXECUTION]: The skill triggers shell scripts (cognee-index-repo.sh, cognee-search.sh, cognee-remember.sh) from the plugin's root directory to interact with the Cognee server, passing repository paths and JSON query objects as arguments.
  • [EXTERNAL_DOWNLOADS]: When a user provides a Git URL for indexing, the Cognee server performs a shallow clone of the remote repository to build the architectural graph.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 12:59 AM