security-review

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a standard security auditing template. It uses benign search patterns and provides correct guidance for remediating common vulnerabilities.
  • [COMMAND_EXECUTION]: The skill uses grep via the Bash tool to identify patterns such as hardcoded secrets and unparameterized SQL queries in the target codebase. These operations are limited to searching local files and align with the skill's stated purpose.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it is designed to ingest and analyze untrusted source code. Maliciously crafted code or comments could attempt to influence the agent's audit report.
  • Ingestion points: Reads source code files via Read, Grep, and Glob tools.
  • Boundary markers: None explicitly defined in the instructions to separate code content from instructions.
  • Capability inventory: Bash, Read, WebSearch.
  • Sanitization: No sanitization or filtering is performed on the ingested code content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:08 PM
Security Audit — agent-trust-hub — security-review