security-scan
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Node.js script located at
.claude/scripts/security-scan.mjs. This script is responsible for the core scanning logic and accepts user-provided arguments via the$ARGUMENTSvariable. - [EXTERNAL_DOWNLOADS]: The skill suggests the installation of
@semgrep/clivia the npm registry. This is a well-known and trusted security analysis tool. - [INDIRECT_PROMPT_INJECTION]: The skill parses and displays findings (code snippets, risk descriptions, and fixes) from external files scanned by the tool. While this represents a surface for indirect injection (e.g., malicious code snippets in the report), the skill uses standard Markdown formatting to display results, which is a typical implementation for reporting tools.
Audit Metadata