secret-scanning

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration references an external service at https://api.githubcopilot.com/mcp/ for secret scanning. This is a well-known service associated with the skill author (github) and is necessary for its documented security-focused purpose.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted data from the repository for scanning.\n
  • Ingestion points: Processes content, file data from the Read tool, and git diff outputs from Bash.\n
  • Boundary markers: The instructions do not specify explicit delimiters to isolate untrusted content from the agent's instructions.\n
  • Capability inventory: The skill utilizes Bash, Read, Glob, and Grep tools.\n
  • Sanitization: No specific sanitization or filtering of the ingested content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 04:18 AM
Security Audit — agent-trust-hub — secret-scanning