codesight-ai-context
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends using
npx codesightornpm install -g codesightto access the tool. This follows standard practices for distributing and running developer utilities via the npm registry. - [COMMAND_EXECUTION]: The provided instructions include a comprehensive list of shell commands used to map project structures, generate documentation, and run a Model Context Protocol (MCP) server for AI assistants.
- [DATA_EXPOSURE]: As a context generator, the tool is designed to read and summarize codebase metadata such as routes, models, and file structures into a local
.codesight/directory. This behavior is the intended primary purpose of the skill and is clearly documented. - [SAFE]: The skill contains no signs of prompt injection, obfuscation, or unauthorized data exfiltration. All external resources and packages are consistent with the identified vendor.
Audit Metadata