ghost-report

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs its primary function of security report aggregation using local findings files. All operations are confined to the repository context and the vendor-specific directory.
  • [COMMAND_EXECUTION]: The skill uses Bash to resolve file paths and repository metadata. These commands use standard utilities like git, basename, and dirname for path calculation and do not involve remote execution or privilege escalation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes findings from external scan files. While this creates an ingestion surface for untrusted data, it is a requirement for the tool's core functionality, and the instructions prioritize objective reporting and redaction of sensitive data like secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:26 PM
Security Audit — agent-trust-hub — ghost-report