security-scan

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to install and run security scanning utilities (git-secrets, gitleaks, and trufflehog). This functionality is expected and required for the skill's purpose of performing a security audit on a codebase.
  • [PROMPT_INJECTION]: The skill processes content from local files via security tools and reports those findings back to the agent's context, creating a surface for indirect prompt injection (Category 8). 1. Ingestion points: File content snippets are ingested via the standard output of the scanning tools. 2. Boundary markers: No specific delimiters or instructions are used to separate tool output from the agent's internal instructions. 3. Capability inventory: The agent has the capability to execute shell commands and read from the local file system. 4. Sanitization: No explicit sanitization or filtering is applied to the data returned by the security tools before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 12:44 AM
Security Audit — agent-trust-hub — security-scan