vulnerability-scanner

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/security_scan.py uses subprocess.run to execute the npm audit command. This is a legitimate security analysis operation performed with a static argument list, which prevents command injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party project files, creating an inherent surface for indirect prompt injection where malicious content in scanned files could attempt to misdirect the AI agent's analysis.
  • Ingestion points: Target project files located in the directory path provided to scripts/security_scan.py and accessed via the Read and Glob tools.
  • Boundary markers: The skill does not implement explicit prompt delimiters, but it uses a separate script to produce structured JSON findings, which provides separation between raw data and agent logic.
  • Capability inventory: The skill possesses file read access, pattern matching capabilities, and the ability to execute the local npm CLI tool.
  • Sanitization: The scanning script uses fixed regular expressions to extract specific security findings, reducing the risk of malicious data being interpreted as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — vulnerability-scanner