code-security
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to run
semgrepfor code scanning andpipfor installing the required dependency in theSKILL.mdand installation scripts. - [EXTERNAL_DOWNLOADS]: The skill and its installer scripts download the
semgreppackage from the official Python Package Index (PyPI). Manual installation also involves fetching theSKILL.mdfile from the author's GitHub repository, which is a known source in this context. - [INDIRECT_PROMPT_INJECTION]: The skill acts as an audit tool that ingests and processes project source code. This creates a surface where malicious code within a project could attempt to influence the agent's reporting, although this is inherent to the auditing use case.
- Ingestion points: The current project directory and specific files/folders targeted for scanning (SKILL.md).
- Boundary markers: None explicitly defined in the prompt instructions to isolate semgrep output.
- Capability inventory: Executes
semgrepandpip(SKILL.md). - Sanitization: No specific sanitization of the semgrep output is performed before presentation to the agent.
- [PRIVILEGE_ESCALATION]: The Windows installation script (
install.ps1) uses the-ExecutionPolicy Bypassflag to permit the execution of the installer script, which is a common administrative practice for local development scripts.
Audit Metadata