security-vuln-scanner-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [SAFE]: The skill's implementation in skill.yaml uses regular expressions to detect security patterns in user-provided text. It does not execute the code, perform network calls, or interact with the operating system in a privileged manner.
  • [PROMPT_INJECTION]: The SKILL.md file contains instructions labeled as 'Security Guardrails.' These are defensive prompts that instruct the agent to redact sensitive information and refuse requests to exfiltrate data. These serve as a safety layer rather than a malicious behavioral override.
  • [CREDENTIALS_UNSAFE]: A hardcoded PostgreSQL connection string is detected in the SAFETY.md file. Technical review confirms this is a mock credential used strictly as an example in a 'Safety Evaluation' document to test secret redaction logic.
  • [SAFE]: All external links and metadata point to the vendor's official infrastructure at faberlens.ai and associated GitHub repositories for the legitimate purpose of providing security analysis reports and feedback mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:32 PM
Security Audit — agent-trust-hub — security-vuln-scanner-hardened