sota
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill methodology defined in
rules/01-audit-methodology.mdprescribes the use of numerous CLI security tools to perform repository analysis, includinggitleaks,trufflehog,bandit,Opengrep,Semgrep,pip-audit,cargo-audit,gosec,govulncheck,trivy,grype, andcheckov. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, which is an inherent surface for indirect prompt injection attacks.
- Ingestion points: As described in
SKILL.md, the skill reads external source code, pull request diffs, CI configurations, and maintainer feedback. - Boundary markers: Operating Principle 0 in
SKILL.mdmandates the validation of every claim against primary sources (code context, official docs, reproduced behavior) rather than internal summaries or rules. - Capability inventory: The skill directs the agent to execute a wide variety of SAST, SCA, and secret scanning tools listed in the tool matrix of
rules/01-audit-methodology.md. - Sanitization: Operating Principle 7 requires the agent to re-read artifacts directly from the source to prevent reliance on potentially poisoned session summaries.
- [EXTERNAL_DOWNLOADS]: The skill refers to local initialization scripts,
scripts/init-gates.shandscripts/gen-agents-md.sh, to be executed for repositories lacking security gates. It also provides a link to report issues at a GitHub repository owned by the skill author.
Audit Metadata