config-setup

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes codemap commands to analyze the repository and verify configuration changes.- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by reading untrusted project files such as package.json, Cargo.toml, and go.mod (ingestion points in SKILL.md) to determine the project stack. There are no explicit boundary markers or sanitization logic mentioned to isolate these inputs. However, the skill's capabilities are limited to writing the .codemap/config.json file, making this a low-risk surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 04:20 AM