semgrep-rule-variant-creator
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user data in the form of existing Semgrep rule YAML content. This introduces a surface for indirect prompt injection where malicious instructions could be embedded in the rule's metadata (e.g., message or description fields) to attempt to influence the agent's porting process.
- Ingestion points: Untrusted YAML content enters the context via user input as specified in
SKILL.mdand processed during thePhase 1: Applicability Analysisdescribed inworkflow.md. - Boundary markers: Absent; the instructions do not currently require the agent to wrap input rule content in specific delimiters or use safety instructions when parsing the YAML.
- Capability inventory: The skill uses
Bash(to run thesemgrepbinary), andWrite/Edit(to produce new rule and test files). - Sanitization: No explicit sanitization or structure validation of the input YAML is documented before the analysis phase.
- [COMMAND_EXECUTION]: The skill instructions and workflow utilize the
Bashtool to execute legitimatesemgrepCLI commands. These include AST dumping (--dump-ast), rule validation (--validate), and regression testing (--test). These are essential, well-documented operations performed on locally created or existing files and do not involve piped remote execution. - [EXTERNAL_DOWNLOADS]: The documentation includes references to the official Semgrep documentation (
semgrep.dev) and security research guidelines from Trail of Bits. These are trusted, well-known service providers and represent safe documentation links rather than the downloading of untrusted scripts or executable payloads.
Audit Metadata