security-scan
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates external security binaries including semgrep, bandit, pip-audit, trivy, and gitleaks to perform code analysis. These commands are invoked using the Python subprocess module with arguments passed as lists, which effectively prevents shell injection vulnerabilities.
- [EXTERNAL_DOWNLOADS]: The skill's documentation directs users to install necessary security dependencies from established repositories, such as the Python Package Index (PyPI) and official GitHub release pages for Trivy and Gitleaks.
- [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill's purpose is to find sensitive data, it includes a redaction mechanism in
secrets.pythat masks detected credentials before they are reported or stored. This minimizes the risk of leaking secrets in the agent's output or history files. - [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection because it processes untrusted project files and external tool outputs which are then returned to the agent.
- Ingestion points: Any source code or configuration files located within the directory targeted by the
--pathoption. - Capability inventory: The skill has the ability to execute system commands via subprocess in
sast.py,deps.py, andsecrets.py. - Boundary markers: Findings are returned as structured data, but there are no specific markers used to distinguish tool-generated descriptions from agent instructions.
- Sanitization: Secret values are redacted, but other metadata from scanned files is passed through without specific sanitization.
Audit Metadata