codebase-singularity

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to operate on external codebases, which serves as a vector for indirect prompt injection if the repository contains malicious instructions.
  • Ingestion points: The skill ingests data from the entire repository provided in the 'Repo path' input.
  • Boundary markers: The instructions do not provide explicit delimiters or instructions for the agent to ignore natural language instructions found within the codebase.
  • Capability inventory: The skill is authorized to perform file writes ('implement the smallest viable patch') and execute shell commands ('run the requested command(s)').
  • Sanitization: There is no evidence of sanitization or filtering of the content read from the repository before it is processed by the agent.
  • [COMMAND_EXECUTION]: The workflow defined in SKILL.md explicitly directs the agent to execute validation commands provided by the user or derived from the project (e.g., tests, build scripts). While this is the intended purpose of the skill, it represents a command execution surface that could be exploited if malicious inputs are provided.
  • [DATA_EXPOSURE]: The reference files references/transcript.md, references/video.md, and references/visual-notes.md contain hardcoded absolute paths from the author's local system (e.g., /Users/vishal/clawd/). These paths expose the author's local username and internal directory structure, which constitutes a minor metadata exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 06:32 PM