security-scan
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to install and run security scanning utilities (git-secrets, gitleaks, and trufflehog). This functionality is expected and required for the skill's purpose of performing a security audit on a codebase.
- [PROMPT_INJECTION]: The skill processes content from local files via security tools and reports those findings back to the agent's context, creating a surface for indirect prompt injection (Category 8). 1. Ingestion points: File content snippets are ingested via the standard output of the scanning tools. 2. Boundary markers: No specific delimiters or instructions are used to separate tool output from the agent's internal instructions. 3. Capability inventory: The agent has the capability to execute shell commands and read from the local file system. 4. Sanitization: No explicit sanitization or filtering is applied to the data returned by the security tools before it is processed by the agent.
Audit Metadata