ripgrep
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The scripts
scripts/probe_ripgrep.pyandscripts/validate.pyexecute thergandshbinaries usingsubprocess.run. These calls use argument lists rather than shell strings, mitigating command injection risks during validation workflows. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied search patterns. It proactively addresses injection risks by instructing the agent to use the
-Fflag for literal matches and single quotes to prevent shell expansion of special characters. - [SAFE]: The skill relies on local environment tools and official project documentation. No remote code execution, data exfiltration, or persistence mechanisms were detected.
Audit Metadata