security-scan

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates external security binaries including semgrep, bandit, pip-audit, trivy, and gitleaks to perform code analysis. These commands are invoked using the Python subprocess module with arguments passed as lists, which effectively prevents shell injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill's documentation directs users to install necessary security dependencies from established repositories, such as the Python Package Index (PyPI) and official GitHub release pages for Trivy and Gitleaks.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill's purpose is to find sensitive data, it includes a redaction mechanism in secrets.py that masks detected credentials before they are reported or stored. This minimizes the risk of leaking secrets in the agent's output or history files.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it processes untrusted project files and external tool outputs which are then returned to the agent.
  • Ingestion points: Any source code or configuration files located within the directory targeted by the --path option.
  • Capability inventory: The skill has the ability to execute system commands via subprocess in sast.py, deps.py, and secrets.py.
  • Boundary markers: Findings are returned as structured data, but there are no specific markers used to distinguish tool-generated descriptions from agent instructions.
  • Sanitization: Secret values are redacted, but other metadata from scanned files is passed through without specific sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — security-scan