cognee-code
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill indexes external codebases and provides extracted architectural facts to the agent's context under '=== Code graph facts ===' headers. This creates an indirect prompt injection surface where malicious content within a repository could attempt to influence the agent's behavior.
- Ingestion points: External code repositories indexed via cognee-index-repo.sh in SKILL.md.
- Boundary markers: Data injection is delimited by '=== Code graph facts ===' markers as specified in SKILL.md.
- Capability inventory: The skill performs graph traversals, impact analysis, and neighborhood exploration via cognee-search.sh in SKILL.md.
- Sanitization: No explicit content sanitization or validation of the indexed code files is mentioned.
- [COMMAND_EXECUTION]: The skill triggers shell scripts (cognee-index-repo.sh, cognee-search.sh, cognee-remember.sh) from the plugin's root directory to interact with the Cognee server, passing repository paths and JSON query objects as arguments.
- [EXTERNAL_DOWNLOADS]: When a user provides a Git URL for indexing, the Cognee server performs a shallow clone of the remote repository to build the architectural graph.
Audit Metadata