secret-scanning
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill communicates with the official GitHub Copilot API at
https://api.githubcopilot.com/mcp/to perform its primary function of secret scanning.\n- [COMMAND_EXECUTION]: Utilizes restricted shell commands such asgit remoteandgit diffto extract repository metadata and staged changes for analysis.\n- [SAFE]: The skill processes untrusted content from local files and git history which presents an indirect prompt injection surface. However, the risk is mitigated as the content is passed to a specific scanning tool and the process is strictly user-initiated.\n- [SAFE]: All external communications and tool usage are restricted to the author's own official services and standard development workflows.
Audit Metadata