indexion-identity

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process and review local project code using the indexion tool.
  • Ingestion points: Local file content, folder structures, and declaration symbols are ingested by the indexion identity audit command in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat external code as untrusted data.
  • Capability inventory: The skill utilizes bash to execute commands like indexion, rg (ripgrep), and moon (build system), and suggests file operations like renaming and moving files.
  • Sanitization: No sanitization is performed on the code content before analysis.
  • [COMMAND_EXECUTION]: The skill uses local CLI tools (indexion, rg, moon) for static analysis and project formatting, which is standard behavior for development-oriented skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:03 AM
Security Audit — agent-trust-hub — indexion-identity