pre-push-security-scan

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill scans local files and Git history to detect sensitive strings. It also includes an optional check that compares local file content against entries in the user's local pass password store. These operations are performed locally to prevent accidental data exposure; no evidence of outbound network transmission or exfiltration was found.
  • [EXTERNAL_DOWNLOADS]: The skill recommends installing git-filter-repo via pip for repository cleanup. This is a widely recognized and reputable tool used for rewriting Git history to remove sensitive data.
  • [COMMAND_EXECUTION]: Utilizes standard developer tools including git, grep, and pass. These commands are used for auditing purposes within the local environment and do not involve untrusted inputs or shell injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 11:51 AM
Security Audit — agent-trust-hub — pre-push-security-scan