skills/jpcaparas/skills/ripgrep/Gen Agent Trust Hub

ripgrep

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts scripts/probe_ripgrep.py and scripts/validate.py execute the rg and sh binaries using subprocess.run. These calls use argument lists rather than shell strings, mitigating command injection risks during validation workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied search patterns. It proactively addresses injection risks by instructing the agent to use the -F flag for literal matches and single quotes to prevent shell expansion of special characters.
  • [SAFE]: The skill relies on local environment tools and official project documentation. No remote code execution, data exfiltration, or persistence mechanisms were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — ripgrep