ai-sast-triage

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill accesses the local Endor configuration file (~/.endorctl/config.yaml) solely to resolve the active namespace. It contains strict prohibitions against dumping the entire file or exposing credentials, and it specifies using field-specific commands to extract only the necessary namespace key.
  • [COMMAND_EXECUTION]: To validate patches, the skill executes build and test commands (such as Maven, npm, or Docker) identified within the target repository. This is an intended functionality for automated remediation and is restricted to the context of the repository being triaged.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Endor findings, source code, and PR comments. It incorporates safety instructions to treat this content as data rather than instructions and provides mandatory rules for sanitizing exploit reproduction evidence before it is included in public-facing pull request bodies.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 06:47 PM
Security Audit — agent-trust-hub — ai-sast-triage