aeon-vuln-scanner
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code from external GitHub repositories during the "Triage" phase to verify findings, creating a surface for indirect prompt injection.
- Ingestion points: The agent is instructed to "Open the file at the reported line" and "Read 30-50 lines of context" from target repositories to determine if a vulnerability is reachable.
- Boundary markers: The instructions do not specify the use of delimiters or "ignore instructions" warnings when the agent reads external file content.
- Capability inventory: The agent has the ability to execute shell commands (security scanners), perform network operations via
gh api, and utilize a providedGITHUB_TOKENfor disclosure. - Sanitization: There is no explicit requirement for the agent to sanitize or filter instructions potentially embedded in the code comments or documentation of target repositories.
- [COMMAND_EXECUTION]: The skill instructs the agent to execute several third-party security scanners (
semgrep,trufflehog,osv-scanner,slither) and the GitHub CLI (gh api) within the local environment. These tools are used for their intended purpose of identifying security flaws and managing responsible disclosure.
Audit Metadata