skills/craftos-dev/craftbot/semgrep/Gen Agent Trust Hub

semgrep

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches enhanced security rules from well-known repositories including Trail of Bits, HashiCorp, and Decurity via Git. It also utilizes the Microsoft SARIF Multitool via npx. These downloads are from trusted vendors and are standard for static analysis workflows.\n- [COMMAND_EXECUTION]: Spawns subagents to execute Semgrep and Git commands. This execution is protected by a structured 5-step workflow and a hard gate in Step 3, ensuring no commands are run until the user has reviewed and explicitly approved the target and rulesets.\n- [PROMPT_INJECTION]: As a code analysis tool, the skill processes untrusted external code. This surface for indirect prompt injection is mitigated by the modular architecture, which separates the orchestration logic from the scanning tasks and includes human verification steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 05:36 PM
Security Audit — agent-trust-hub — semgrep