security-ai-keys

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local data (source code, log files, and configuration files) using ripgrep to identify secret patterns. This ingestion of external data creates a potential surface for indirect prompt injection if the files being scanned contain malicious instructions designed to influence the agent's interpretation of the scan results.
  • Ingestion points: Local files in the directory specified by the user are read via rg (ripgrep) in scripts/scan.sh and the provided shell commands.
  • Boundary markers: None identified in the script or instructions to delimit scanned content from agent instructions.
  • Capability inventory: The skill uses ripgrep for file reading and displays findings to the standard output.
  • Sanitization: No specific sanitization or escaping of the scanned file content is performed before the agent processes the results.
  • [COMMAND_EXECUTION]: The skill provides shell commands and a script (scripts/scan.sh) that execute ripgrep (rg) to search through the filesystem. These commands are localized to the user-provided directory and are consistent with the skill's stated purpose of auditing for security leaks.
  • [DATA_EXPOSURE]: The skill explicitly targets sensitive information, including API keys for various AI providers (OpenAI, Anthropic, Gemini, etc.) and cloud credentials (AWS, Azure, Google Cloud). This access is the primary and intended purpose of the skill; however, the skill does not include any network exfiltration capabilities, ensuring the identified secrets remain local to the user's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:49 PM