security-review
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a standard security auditing template. It uses benign search patterns and provides correct guidance for remediating common vulnerabilities.
- [COMMAND_EXECUTION]: The skill uses
grepvia theBashtool to identify patterns such as hardcoded secrets and unparameterized SQL queries in the target codebase. These operations are limited to searching local files and align with the skill's stated purpose. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it is designed to ingest and analyze untrusted source code. Maliciously crafted code or comments could attempt to influence the agent's audit report.
- Ingestion points: Reads source code files via
Read,Grep, andGlobtools. - Boundary markers: None explicitly defined in the instructions to separate code content from instructions.
- Capability inventory:
Bash,Read,WebSearch. - Sanitization: No sanitization or filtering is performed on the ingested code content.
Audit Metadata