vulnerability-scanner

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/security_scan.py executes the npm audit command locally to identify vulnerabilities in dependencies. The command is invoked using a static argument list which prevents command injection vulnerabilities.- [DATA_EXFILTRATION]: The skill identifies and reports on sensitive data such as API keys and credentials found within a project's files. Analysis of the skill's scripts confirms that no data is transmitted to external servers or unauthorized domains.- [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection as it processes content from untrusted local files. However, the risk is minimized because the scanning script produces structured JSON output, which prevents the agent from directly executing instructions that might be embedded in the scanned files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 09:21 AM
Security Audit — agent-trust-hub — vulnerability-scanner