code-analyzer
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requests and utilizes
BashandTasktools. These capabilities are intended for module discovery, identifying technical stacks, and managing the documentation workflow within the user's filesystem. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external code modules.
- Ingestion points: Source code files read during 'Step 1: Discovery' and 'Step 2: Deep Analysis' in SKILL.md.
- Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or to disregard instructions found within the analyzed code content.
- Capability inventory: A wide range of tools is available to the agent, including
Bash,Task,Read,Write, andEdit. - Sanitization: No procedures are defined for sanitizing or escaping instructions that might be embedded in the analyzed source code files.
Audit Metadata