secure-ai-agent-coding

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to ingest and analyze external, untrusted codebases through scripts/scan_patterns.py.
  • Ingestion points: scripts/scan_patterns.py reads the content of arbitrary text files within a target directory provided as a command-line argument.
  • Boundary markers: While the skill documentation in references/implementation-patterns.md strongly advocates for the use of boundary markers (e.g., <untrusted_user_data> tags), the heuristic scanner script itself reads raw file content directly into regex engines.
  • Capability inventory: The skill has the capability to read local files, write JSON results to stdout, and execute internal scripts via subprocess.run in the test suite.
  • Sanitization: The scanner does not sanitize the input files; it performs heuristic regex matching to identify potential vulnerabilities for human review.
  • [COMMAND_EXECUTION]: The testing script scripts/test_skill.py utilizes the subprocess.run module to execute other scripts within the skill's package.
  • Evidence: scripts/test_skill.py executes scripts/validate.py and scripts/scan_patterns.py using sys.executable.
  • Context: These executions are used for validating the skill's integrity and functionality. The commands are constructed using fixed paths relative to the skill root, minimizing injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — secure-ai-agent-coding