repo-scan
Warn
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation instructions require cloning a repository from an untrusted community source (https://github.com/haibindev/repo-scan.git). This process downloads external code that the agent will subsequently use, which has not been verified for safety.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by scanning local source code repositories. This presents an attack surface where malicious instructions hidden in the code (e.g., in comments or license files) could influence the agent's behavior. Ingestion points include the entire directory surface as described in SKILL.md. No boundary markers or sanitization processes are mentioned, and the skill possesses the capability to execute shell commands and write to the file system during installation and reporting.
Audit Metadata