code-communities
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands (
find,grep,rg,sed,sort) to inspect the project's file structure and import statements for architectural mapping.- [COMMAND_EXECUTION]: It dynamically locates and executes a local script (graph_query.py) from a specific plugin directory (~/.claude/plugins/) to perform advanced graph analysis when the tool is present.- [SAFE]: Analysis of local code files presents a theoretical surface for indirect prompt injection. 1. Ingestion points:findandrgoutput from local.pyfiles. 2. Boundary markers: None. 3. Capability inventory: Shell command execution and Python script execution. 4. Sanitization: None. The risk is considered minimal as the skill's output is limited to structural summaries and Mermaid diagrams.
Audit Metadata