code-analyzer

Pass

Audited by Gen Agent Trust Hub on Mar 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requests and utilizes Bash and Task tools. These capabilities are intended for module discovery, identifying technical stacks, and managing the documentation workflow within the user's filesystem.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external code modules.
  • Ingestion points: Source code files read during 'Step 1: Discovery' and 'Step 2: Deep Analysis' in SKILL.md.
  • Boundary markers: Absent. The skill does not instruct the agent to use specific delimiters or to disregard instructions found within the analyzed code content.
  • Capability inventory: A wide range of tools is available to the agent, including Bash, Task, Read, Write, and Edit.
  • Sanitization: No procedures are defined for sanitizing or escaping instructions that might be embedded in the analyzed source code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 10, 2026, 07:30 AM