indexion-kgf

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the indexion kgf update and indexion kgf add commands, which fetch language specifications from GitHub. This is a standard operational feature for keeping language support up to date.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for parsing and inspecting arbitrary source files, which constitutes a potential ingestion surface for untrusted data.
  • Ingestion points: Commands such as indexion kgf inspect <file>, indexion kgf tokens <file>, indexion kgf events <file>, and indexion kgf edges <file> in SKILL.md ingest external source code files.
  • Boundary markers: None are specified in the command instructions; the tool processes the files directly based on provided paths.
  • Capability inventory: The skill uses shell execution to run the indexion utility, which outputs tokens, parse events, and dependency edges to the console.
  • Sanitization: No explicit sanitization or filtering of the input file content is documented in the skill instructions, as it is a debugging tool for raw parsing output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 01:03 AM
Security Audit — agent-trust-hub — indexion-kgf