security-auditor
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/detect-secrets.shuses theevalcommand to execute afindoperation that incorporates the$TARGET_DIRvariable. Because the variable is placed inside single quotes within theevalstring without sanitization, a directory name containing a single quote followed by shell commands (e.g.,path/to/repo' ; id ; ') would result in arbitrary command execution when the script is run by the agent. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted source code from external codebases. It lacks robust boundary markers or sanitization when extracting 'evidence' from these files for its reports. This creates an attack surface where a malicious codebase could provide crafted input to influence the auditor's output or exploit the processing logic.
- Ingestion points: Source code files, directory paths, and package manifests (package.json, requirements.txt) processed by the scripts in the
scripts/directory. - Boundary markers: The skill does not implement explicit delimiters or instructions to the agent to ignore embedded commands within the files being audited.
- Capability inventory: The skill is granted broad capabilities including
Read,Write,Edit, andBash(restricted tonpm audit,pip-audit,grep, andfind). - Sanitization: No sanitization is performed on file paths or content before they are used in shell commands or report generation logic.
Audit Metadata