security-auditor

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/detect-secrets.sh uses the eval command to execute a find operation that incorporates the $TARGET_DIR variable. Because the variable is placed inside single quotes within the eval string without sanitization, a directory name containing a single quote followed by shell commands (e.g., path/to/repo' ; id ; ') would result in arbitrary command execution when the script is run by the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted source code from external codebases. It lacks robust boundary markers or sanitization when extracting 'evidence' from these files for its reports. This creates an attack surface where a malicious codebase could provide crafted input to influence the auditor's output or exploit the processing logic.
  • Ingestion points: Source code files, directory paths, and package manifests (package.json, requirements.txt) processed by the scripts in the scripts/ directory.
  • Boundary markers: The skill does not implement explicit delimiters or instructions to the agent to ignore embedded commands within the files being audited.
  • Capability inventory: The skill is granted broad capabilities including Read, Write, Edit, and Bash (restricted to npm audit, pip-audit, grep, and find).
  • Sanitization: No sanitization is performed on file paths or content before they are used in shell commands or report generation logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 04:08 AM
Security Audit — agent-trust-hub — security-auditor