security-scan
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides recipes for running several security tools via shell commands (Semgrep, osv-scanner, gitleaks, TruffleHog, Trivy). These are legitimate uses for the skill's purpose of orchestrating security sweeps.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted output from various security scanners (SARIF/JSON logs). While this presents a potential attack surface for indirect prompt injection if an attacker-controlled file causes a scanner to emit malicious instructions, the skill implements strong mitigation practices:
- Ingestion points: Processes external scan logs (
sast.sarif,sca.sarif,secrets.sarif,trivy.sarif). - Capability inventory: Performs file reads of log files and shell execution of scanners, but maintains a 'read-only by default' policy for the codebase itself.
- Sanitization: The instructions explicitly require normalizing scanner output into a structured, machine-checkable JSON schema (
security-scan-report.json) before triage, which limits the influence of free-text scanner descriptions. - [SAFE]: The skill contains significant security best-practice guidance, specifically warning about a historical supply-chain compromise of the 'Trivy' scanner in March 2026 and enforcing the pinning of tools to specific versions or commit SHAs to prevent supply-chain attacks.
Audit Metadata