security-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted code and configurations using the Read, Grep, and Glob tools. Without explicit boundary markers or instructions to isolate the audited content, a malicious payload in a target file could influence the agent to perform unauthorized actions. Evidence chain: 1) Ingestion points: Local file content read from the filesystem. 2) Boundary markers: Absent from the instructions. 3) Capability inventory: Access to the Bash tool for command execution. 4) Sanitization: No validation or escaping of file content is required.
  • [COMMAND_EXECUTION]: The skill explicitly uses the Bash tool to run powerful security utilities like nmap, sqlmap, and various cloud CLIs. While appropriate for the role, this broad access increases the impact of potential indirect injection attacks.
  • [EXTERNAL_DOWNLOADS]: The skill instructions and references suggest installing numerous tools from external repositories, such as pip install bandit and brew install trivy, and fetching data from well-known services like crt.sh for reconnaissance. These actions represent standard external dependencies for a security workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:06 AM
Security Audit — agent-trust-hub — security-reviewer