security-reviewer
Pass
Audited by Gen Agent Trust Hub on Mar 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill extensively utilizes the
Bashtool to execute a variety of security utilities, includingnmapfor port scanning,sqlmapfor injection testing, and cloud CLI tools (aws,az,gcloud) for infrastructure auditing. These operations are core to the skill's defined role and are governed by included 'Rules of Engagement'. - [EXTERNAL_DOWNLOADS]: The documentation provides instructions for installing and running several well-known security tools (e.g.,
gitleaks,trufflehog,checkov,semgrep,bandit) from official public repositories and registries like GitHub, npm, and PyPI. All referenced external services (e.g.,crt.sh,Snyk,HashiCorp Vault) are recognized technology providers. - [DATA_EXFILTRATION]: The skill includes command templates for reconnaissance and secret discovery, such as searching for hardcoded credentials, API keys, and JWTs in source code, logs, and shell history. These functions are intended for vulnerability identification during authorized security audits and are not directed at unauthorized exfiltration to unknown third parties.
- [PROMPT_INJECTION]: As a security reviewer, the skill inherently processes untrusted external data (source code and logs), which presents an indirect prompt injection surface.
- Ingestion points: Files are ingested into the agent context via the
Read,Grep, andGlobtools. - Boundary markers: The instructions do not specify explicit delimiters or 'ignore embedded instructions' warnings for processed code.
- Capability inventory: The skill has access to the
Bashtool, allowing for shell command execution based on findings. - Sanitization: While no specific prompt-level sanitization is documented, the skill includes 'Proof of Concept Guidelines' and 'Rules of Engagement' to ensure the agent performs impact validation safely.
Audit Metadata