code-security

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to run semgrep for code scanning and pip for installing the required dependency in the SKILL.md and installation scripts.
  • [EXTERNAL_DOWNLOADS]: The skill and its installer scripts download the semgrep package from the official Python Package Index (PyPI). Manual installation also involves fetching the SKILL.md file from the author's GitHub repository, which is a known source in this context.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as an audit tool that ingests and processes project source code. This creates a surface where malicious code within a project could attempt to influence the agent's reporting, although this is inherent to the auditing use case.
  • Ingestion points: The current project directory and specific files/folders targeted for scanning (SKILL.md).
  • Boundary markers: None explicitly defined in the prompt instructions to isolate semgrep output.
  • Capability inventory: Executes semgrep and pip (SKILL.md).
  • Sanitization: No specific sanitization of the semgrep output is performed before presentation to the agent.
  • [PRIVILEGE_ESCALATION]: The Windows installation script (install.ps1) uses the -ExecutionPolicy Bypass flag to permit the execution of the installer script, which is a common administrative practice for local development scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 02:47 PM