env-scanner

Warn

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is instructed in SKILL.md to read sensitive files such as .env, .env.local, and .env.sample. It records the values of these variables—including those classified as credential (e.g., keys, secrets, tokens)—into a generated CONFIG-MAP.md file. This practice exposes sensitive secrets in plaintext within the project directory.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from the codebase which could contain malicious instructions.
  • Ingestion points: SKILL.md Step 1 directs the agent to ingest source code, CI/CD manifests, and environment files.
  • Boundary markers: Absent; no instructions are provided to treat ingested content as untrusted or to use delimiters.
  • Capability inventory: SKILL.md Step 4 grants the agent file-writing capabilities to create the report.
  • Sanitization: Absent; the skill does not include steps to sanitize or escape the content before it is interpolated into the final report.
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md and references/gotchas.md specify the use of shell commands like grep to perform codebase-wide searches. This involves automated access to various file paths, including sensitive configuration files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 23, 2026, 04:55 AM
Security Audit — agent-trust-hub — env-scanner