security-review

Fail

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: CRITICALCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides the agent with specific shell commands and patterns using grep and bash to search for security flaws. These tools are used legitimately to perform the skill's primary function of code auditing.
  • [DATA_EXPOSURE]: The skill contains examples of sensitive data patterns, such as hardcoded API keys and credentials, in its reference material. These are placeholders used to teach the agent what to identify in user code and are not actual secrets.
  • [REMOTE_CODE_EXECUTION]: The documentation includes code snippets demonstrating how remote code execution vulnerabilities occur in various languages. These snippets are strictly instructional and are not executed by the skill itself.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted code provided by users, creating an attack surface for indirect prompt injection. Maliciously crafted source code or filenames could attempt to influence the agent's behavior during the review process. The skill provides clear guidelines for the agent to verify data flow and framework protections to minimize the impact of such attempts.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 14, 2026, 01:43 PM
Security Audit — agent-trust-hub — security-review