appsec
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes repository-local files and a custom policy file (POLICY.md) to perform its security scans. This data ingestion creates a surface for indirect prompt injection where malicious instructions embedded in the repository could attempt to influence the agent's behavior during the triage and attestation process.
- Ingestion points: The check-policy.sh script and various scanners (semgrep, trivy, gitleaks) read the entire source tree and local configuration files.
- Boundary markers: The instructions emphasize a deterministic enforcement path for the scanner, but the agent remains responsible for reviewing tool outputs which may contain untrusted strings.
- Capability inventory: The skill has access to powerful tools including git, syft, and multiple security scanners.
- Sanitization: The custom policy scanner script implements robust shell practices, such as NUL-delimited path handling, to mitigate common command injection risks.
Audit Metadata