security-vuln-scanner-hardened
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [SAFE]: The skill's implementation in
skill.yamluses regular expressions to detect security patterns in user-provided text. It does not execute the code, perform network calls, or interact with the operating system in a privileged manner. - [PROMPT_INJECTION]: The
SKILL.mdfile contains instructions labeled as 'Security Guardrails.' These are defensive prompts that instruct the agent to redact sensitive information and refuse requests to exfiltrate data. These serve as a safety layer rather than a malicious behavioral override. - [CREDENTIALS_UNSAFE]: A hardcoded PostgreSQL connection string is detected in the
SAFETY.mdfile. Technical review confirms this is a mock credential used strictly as an example in a 'Safety Evaluation' document to test secret redaction logic. - [SAFE]: All external links and metadata point to the vendor's official infrastructure at
faberlens.aiand associated GitHub repositories for the legitimate purpose of providing security analysis reports and feedback mechanisms.
Audit Metadata