vulnerability-scanner
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
scripts/security_scan.pyscript processes files within a user-provided project directory. This represents a potential surface for indirect prompt injection if malicious files are crafted to influence the agent's interpretation of the scan results. - Ingestion points: Files within the directory specified by the
project_pathargument inscripts/security_scan.pyare read and analyzed. - Boundary markers: No specific delimiters or instructions are used to prevent the agent from misinterpreting embedded instructions found within scanned files.
- Capability inventory: The script uses
subprocess.runto callnpm auditand performs standard file reading operations. - Sanitization: The script uses regular expressions for pattern matching and
json.loads()for parsing tool output, but does not sanitize the raw content of the files it scans. - [COMMAND_EXECUTION]: The script
scripts/security_scan.pyusessubprocess.runto execute thenpm auditcommand. - The execution is used to perform dependency auditing as part of the skill's stated purpose.
- The command
npm audit --jsonis executed within the context of the user-suppliedproject_pathusing the standard librarysubprocessmodule.
Audit Metadata