hol-guard

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for the installation of the author's security-focused CLI tools. Installation is performed using pipx or pip with the --user flag, avoiding privilege escalation.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to scan and analyze external artifacts like plugins, skills, and MCP servers. * Ingestion points: The plugin-scanner and hol-guard commands process local file paths and marketplace packages. * Boundary markers: No explicit boundary markers or delimiters for untrusted content are defined in the skill instructions. * Capability inventory: The skill performs file system analysis and verification through CLI commands. * Sanitization: The instructions do not detail specific sanitization steps, relying on the internal logic of the scanner tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 03:46 AM
Security Audit — agent-trust-hub — hol-guard