security-scanner
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill clones source code from user-provided GitHub repositories using the 'gh repo clone' command when no local project context is detected. This is a functional requirement for auditing remote codebases.
- [COMMAND_EXECUTION]: Uses shell commands to manage the audit environment, including 'mkdir -p' for report organization and 'gh' for repository management. These commands are constrained to the skill's operational purpose.
- [PROMPT_INJECTION]: The skill processes untrusted external codebases, which represents a surface for indirect prompt injection. This is addressed by explicit instructional guardrails requiring the agent to perform read-only analysis and forbidding any modifications to source files.
Audit Metadata