production-audit

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and analyzing untrusted application source code, creating a surface for indirect prompt injection.
  • Ingestion points: Processes entire application repositories, including product documentation, configuration files, and source code (SKILL.md).
  • Boundary markers: Includes a specific subagent brief that instructs the AI to ignore any instructions encountered within the audited codebase (SKILL.md).
  • Capability inventory: The skill possesses capabilities to execute shell commands for scanning secrets and dependencies, write audit reports to the local file system, and perform network requests (SKILL.md).
  • Sanitization: Implements a multi-phase audit process where findings are subjected to adversarial verification by independent skeptic subagents to filter out invalid or malicious results (SKILL.md).
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to interact with vendor infrastructure and well-known services.
  • Evidence: Executes a version check via curl to foundry.thehorizonfoundry.com, which is a vendor-owned domain (SKILL.md).
  • Evidence: References the canonical report schema hosted on the vendor's GitHub repository (SKILL.md).
  • Evidence: Utilizes npx ajv-cli for report validation, which may involve downloading the package from the npm registry (SKILL.md).
  • [COMMAND_EXECUTION]: The skill uses local shell commands to automate mechanical audit tasks.
  • Evidence: Executes tools like npm audit, gitleaks, trufflehog, and ajv-cli to perform dependency analysis, secret scanning, and schema validation (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 11:45 AM
Security Audit — agent-trust-hub — production-audit