hardcoded-credential-finder

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill file consists entirely of metadata, descriptive text, and usage instructions. No executable scripts, shell commands, or network operations are included in the provided content.
  • [PROMPT_INJECTION]: The skill is intended to scan external codebases for credentials, which introduces an indirect prompt injection surface. While the documentation does not currently specify boundary markers or sanitization techniques, there are no instructions present that would cause the agent to execute adversarial content found during a scan.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 02:29 PM