scroll-engineering

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is purely instructional and contains no executable scripts or binaries. It guides the agent through a manual or automated audit process.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or sensitive file paths were detected. The skill uses a default local directory for reporting audit results.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts. All auditing is performed on the user's provided codebase or live URL using standard agent tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data (code or UI behavior) for auditing. While this creates a theoretical attack surface for indirect prompt injection, the risk is minimal as the skill's capabilities are restricted to generating a text-based audit report and it explicitly forbids the agent from implementing code changes based on the audit.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:26 PM
Security Audit — agent-trust-hub — scroll-engineering