repo-scan

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation guide for this skill explicitly instructs users to fetch code from a third-party GitHub repository (haibindev/repo-scan) that is not associated with a trusted organization or the skill author.
  • [REMOTE_CODE_EXECUTION]: By downloading and running external logic from an unverified source as an agent skill, the agent may execute potentially malicious or unauthorized commands within the user environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data from source code repositories, creating a vector for indirect injection attacks.
  • Ingestion points: The skill reads file contents, directory names, file headers, and license markers during the classification and detection phases (SKILL.md).
  • Boundary markers: The instructions do not define any delimiters or system-level directives to prevent the agent from executing instructions found within the scanned repository files.
  • Capability inventory: The skill possesses the capability to classify files, score modules based on content, and generate reports.
  • Sanitization: There is no evidence of sanitization or validation of the data read from external repositories before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — repo-scan