repo-scan

Fail

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instructions direct the agent to fetch external code from an unverified GitHub repository: https://github.com/haibindev/repo-scan.git.
  • [COMMAND_EXECUTION]: The skill uses a sequence of shell commands (git init, git fetch, git checkout, cp) to download and install this external code into the agent's local directory (~/.claude/skills/repo-scan).
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to scan and process untrusted external source code files.
  • Ingestion points: Local source code files within repositories targeted for scanning.
  • Boundary markers: Absent; there are no instructions to ignore or delimit embedded commands within the scanned files.
  • Capability inventory: Extensive file system reading and generation of interactive HTML reports.
  • Sanitization: Absent; the skill does not specify any validation or filtering of the content being analyzed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — repo-scan