vulnerability-scanner
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to ingest and interpret data from untrusted external project files.
- Ingestion points: The skill uses
Read,Glob, andGreptools, along with thescripts/security_scan.pyscript, to read and process content from a user-specified project directory. - Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores or sanitizes potential instructions embedded within code comments, documentation, or configuration files in the scanned project.
- Capability inventory: The skill has the capability to execute shell commands via the
Bashtool and thesubprocessmodule in the included Python script. - Sanitization: No sanitization or validation of the retrieved content is performed before it is presented to the agent for analysis.
- [COMMAND_EXECUTION]: The
scripts/security_scan.pyscript utilizes thesubprocess.runmethod to execute system commands, specificallynpm audit, to perform dependency vulnerability assessments. - [EXTERNAL_DOWNLOADS]: The skill performs network operations by executing
npm audit, which connects to the official npm registry to fetch current vulnerability data. This is documented as a standard and safe operation for dependency auditing.
Audit Metadata