env-scanner
Warn
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is instructed in
SKILL.mdto read sensitive files such as.env,.env.local, and.env.sample. It records the values of these variables—including those classified ascredential(e.g., keys, secrets, tokens)—into a generatedCONFIG-MAP.mdfile. This practice exposes sensitive secrets in plaintext within the project directory. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from the codebase which could contain malicious instructions.
- Ingestion points:
SKILL.mdStep 1 directs the agent to ingest source code, CI/CD manifests, and environment files. - Boundary markers: Absent; no instructions are provided to treat ingested content as untrusted or to use delimiters.
- Capability inventory:
SKILL.mdStep 4 grants the agent file-writing capabilities to create the report. - Sanitization: Absent; the skill does not include steps to sanitize or escape the content before it is interpolated into the final report.
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdandreferences/gotchas.mdspecify the use of shell commands likegrepto perform codebase-wide searches. This involves automated access to various file paths, including sensitive configuration files.
Audit Metadata