indexion-kgf
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the
indexion kgf updateandindexion kgf addcommands, which fetch language specifications from GitHub. This is a standard operational feature for keeping language support up to date. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for parsing and inspecting arbitrary source files, which constitutes a potential ingestion surface for untrusted data.
- Ingestion points: Commands such as
indexion kgf inspect <file>,indexion kgf tokens <file>,indexion kgf events <file>, andindexion kgf edges <file>inSKILL.mdingest external source code files. - Boundary markers: None are specified in the command instructions; the tool processes the files directly based on provided paths.
- Capability inventory: The skill uses shell execution to run the
indexionutility, which outputs tokens, parse events, and dependency edges to the console. - Sanitization: No explicit sanitization or filtering of the input file content is documented in the skill instructions, as it is a debugging tool for raw parsing output.
Audit Metadata