ghost-scan-deps

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill downloads and executes an installation script from the author's official GitHub repository (https://raw.githubusercontent.com/ghostsecurity/wraith/main/scripts/install.sh) to set up the wraith scanner binary.
  • [COMMAND_EXECUTION]: The skill uses shell commands to execute the wraith binary for dependency scanning and uses git commands to determine repository metadata for reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted third-party data to determine if vulnerabilities are exploitable, which creates a potential surface for indirect prompt injection.
  • Ingestion points: Dependency lockfiles (e.g., package-lock.json, go.mod), scanner JSON output, and repository source code files accessed via Grep and Read tools in agents/analyze/analyzer.md.
  • Boundary markers: The analyzer.md prompt instructs the agent to focus on specific exploitability criteria, but it does not employ strict delimiters or 'ignore' instructions for the source code it processes.
  • Capability inventory: The skill utilizes the Task tool to orchestrate subagents, and subagents have access to Bash, Read, Grep, and Glob tools to perform their analysis.
  • Sanitization: No pre-processing or sanitization is applied to the source code snippets or vulnerability data before they are evaluated by the AI agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 05:27 AM
Security Audit — agent-trust-hub — ghost-scan-deps