security-scan

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides recipes for running several security tools via shell commands (Semgrep, osv-scanner, gitleaks, TruffleHog, Trivy). These are legitimate uses for the skill's purpose of orchestrating security sweeps.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted output from various security scanners (SARIF/JSON logs). While this presents a potential attack surface for indirect prompt injection if an attacker-controlled file causes a scanner to emit malicious instructions, the skill implements strong mitigation practices:
  • Ingestion points: Processes external scan logs (sast.sarif, sca.sarif, secrets.sarif, trivy.sarif).
  • Capability inventory: Performs file reads of log files and shell execution of scanners, but maintains a 'read-only by default' policy for the codebase itself.
  • Sanitization: The instructions explicitly require normalizing scanner output into a structured, machine-checkable JSON schema (security-scan-report.json) before triage, which limits the influence of free-text scanner descriptions.
  • [SAFE]: The skill contains significant security best-practice guidance, specifically warning about a historical supply-chain compromise of the 'Trivy' scanner in March 2026 and enforcing the pinning of tools to specific versions or commit SHAs to prevent supply-chain attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — security-scan