aeon-vuln-scanner

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted source code from external GitHub repositories during the "Triage" phase to verify findings, creating a surface for indirect prompt injection.
  • Ingestion points: The agent is instructed to "Open the file at the reported line" and "Read 30-50 lines of context" from target repositories to determine if a vulnerability is reachable.
  • Boundary markers: The instructions do not specify the use of delimiters or "ignore instructions" warnings when the agent reads external file content.
  • Capability inventory: The agent has the ability to execute shell commands (security scanners), perform network operations via gh api, and utilize a provided GITHUB_TOKEN for disclosure.
  • Sanitization: There is no explicit requirement for the agent to sanitize or filter instructions potentially embedded in the code comments or documentation of target repositories.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute several third-party security scanners (semgrep, trufflehog, osv-scanner, slither) and the GitHub CLI (gh api) within the local environment. These tools are used for their intended purpose of identifying security flaws and managing responsible disclosure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — aeon-vuln-scanner