vulnerability-scanner
Pass
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/security_scan.pyexecutes thenpm auditcommand locally to identify vulnerabilities in dependencies. The command is invoked using a static argument list which prevents command injection vulnerabilities.- [DATA_EXFILTRATION]: The skill identifies and reports on sensitive data such as API keys and credentials found within a project's files. Analysis of the skill's scripts confirms that no data is transmitted to external servers or unauthorized domains.- [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it processes content from untrusted local files. However, the risk is minimized because the scanning script produces structured JSON output, which prevents the agent from directly executing instructions that might be embedded in the scanned files.
Audit Metadata