skills/aeondave/malskill/semgrep/Gen Agent Trust Hub

semgrep

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation, example command lines, and rule templates for Semgrep, which is a legitimate security tool for finding vulnerabilities in code. All external references are to the Semgrep registry (p/...) or generic placeholders.
  • [REMOTE_CODE_EXECUTION]: While the skill contains examples of dangerous functions like eval(), os.system(), and subprocess.call(), these are explicitly provided as patterns for the tool to find during security scans, rather than instructions for the agent to execute itself.
  • [COMMAND_EXECUTION]: The skill documents standard CLI usage of the semgrep tool. No malicious or unauthorized command execution patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — semgrep