repo-scan
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The installation guide for this skill explicitly instructs users to fetch code from a third-party GitHub repository (haibindev/repo-scan) that is not associated with a trusted organization or the skill author.
- [REMOTE_CODE_EXECUTION]: By downloading and running external logic from an unverified source as an agent skill, the agent may execute potentially malicious or unauthorized commands within the user environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from source code repositories, creating a vector for indirect injection attacks.
- Ingestion points: The skill reads file contents, directory names, file headers, and license markers during the classification and detection phases (SKILL.md).
- Boundary markers: The instructions do not define any delimiters or system-level directives to prevent the agent from executing instructions found within the scanned repository files.
- Capability inventory: The skill possesses the capability to classify files, score modules based on content, and generate reports.
- Sanitization: There is no evidence of sanitization or validation of the data read from external repositories before it is processed by the agent.
Audit Metadata