security-scan

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Node.js script located at .claude/scripts/security-scan.mjs. This script is responsible for the core scanning logic and accepts user-provided arguments via the $ARGUMENTS variable.
  • [EXTERNAL_DOWNLOADS]: The skill suggests the installation of @semgrep/cli via the npm registry. This is a well-known and trusted security analysis tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill parses and displays findings (code snippets, risk descriptions, and fixes) from external files scanned by the tool. While this represents a surface for indirect injection (e.g., malicious code snippets in the report), the skill uses standard Markdown formatting to display results, which is a typical implementation for reporting tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 05:36 AM
Security Audit — agent-trust-hub — security-scan