walkthrough
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill acts as a guided documentation and analysis tool. Its operations are limited to reading and summarizing the codebase provided by the user. It does not perform network requests to non-whitelisted domains or attempt to escalate privileges. While it instructs the agent to search for connection strings and environment variables in the project files, this is performed to identify the architectural components and stack rather than for exfiltration.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it analyzes untrusted external data (the user-provided codebase) which may contain malicious instructions in comments, documentation, or string literals.
- Ingestion points: All files within the analyzed repository (referenced in SKILL.md and steps 1 through 7).
- Boundary markers: Not present. The instructions do not specify how the agent should handle or ignore natural language instructions found within the code being analyzed.
- Capability inventory: The agent performs file reading, content searching, and provides summaries based on the discovered content.
- Sanitization: Not present. Data extracted from the codebase is presented to the user or used to inform subsequent analysis steps without explicit validation against instruction-like patterns.
Audit Metadata