security-scanner

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because its primary function is to ingest and analyze untrusted codebase content.
  • Ingestion points: The skill reads source code, configuration files, and metadata from target repositories cloned via user-supplied URLs (SKILL.md, Step 1 and Step 3).
  • Boundary markers: The instructions do not provide explicit delimiters or instructions for the agent to differentiate between the data being audited and instructions for the agent itself, nor does it warn to ignore embedded instructions found in comments or strings.
  • Capability inventory: The agent can clone repositories, read and list files, create directories, and write audit reports (SKILL.md, Steps 1, 3, and 4).
  • Sanitization: No sanitization or filtering of the ingested code content is performed before the agent processes it for report generation.
  • [EXTERNAL_DOWNLOADS]: The skill uses the GitHub CLI to download external codebases for analysis when no local source is found (SKILL.md, Step 1). This is a functional requirement for a remote audit tool.
  • [DATA_EXFILTRATION]: The skill is designed to locate and read sensitive files, including .env, configuration settings, and database access logic, to audit them for security misconfigurations and hardcoded secrets (SKILL.md, Step 2 and Step 3). While this is the intended purpose of the tool, it involves intentional access to credential-bearing files.
  • [COMMAND_EXECUTION]: Static analysis flagged the use of eval and exec patterns in documentation reference files (references/A05-injection.md and references/A08-software-data-integrity-failures.md). These occurrences are educational examples describing vulnerabilities to look for and are not part of the skill's own executable logic, making this a false positive.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 03:56 PM