codesight-ai-context

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends using npx codesight or npm install -g codesight to access the tool. This follows standard practices for distributing and running developer utilities via the npm registry.
  • [COMMAND_EXECUTION]: The provided instructions include a comprehensive list of shell commands used to map project structures, generate documentation, and run a Model Context Protocol (MCP) server for AI assistants.
  • [DATA_EXPOSURE]: As a context generator, the tool is designed to read and summarize codebase metadata such as routes, models, and file structures into a local .codesight/ directory. This behavior is the intended primary purpose of the skill and is clearly documented.
  • [SAFE]: The skill contains no signs of prompt injection, obfuscation, or unauthorized data exfiltration. All external resources and packages are consistent with the identified vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 05:20 AM