vulnerability-scanner

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to ingest and interpret data from untrusted external project files.
  • Ingestion points: The skill uses Read, Glob, and Grep tools, along with the scripts/security_scan.py script, to read and process content from a user-specified project directory.
  • Boundary markers: There are no explicit instructions or delimiters used to ensure the agent ignores or sanitizes potential instructions embedded within code comments, documentation, or configuration files in the scanned project.
  • Capability inventory: The skill has the capability to execute shell commands via the Bash tool and the subprocess module in the included Python script.
  • Sanitization: No sanitization or validation of the retrieved content is performed before it is presented to the agent for analysis.
  • [COMMAND_EXECUTION]: The scripts/security_scan.py script utilizes the subprocess.run method to execute system commands, specifically npm audit, to perform dependency vulnerability assessments.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations by executing npm audit, which connects to the official npm registry to fetch current vulnerability data. This is documented as a standard and safe operation for dependency auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:46 AM
Security Audit — agent-trust-hub — vulnerability-scanner