sota

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill methodology defined in rules/01-audit-methodology.md prescribes the use of numerous CLI security tools to perform repository analysis, including gitleaks, trufflehog, bandit, Opengrep, Semgrep, pip-audit, cargo-audit, gosec, govulncheck, trivy, grype, and checkov.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, which is an inherent surface for indirect prompt injection attacks.
  • Ingestion points: As described in SKILL.md, the skill reads external source code, pull request diffs, CI configurations, and maintainer feedback.
  • Boundary markers: Operating Principle 0 in SKILL.md mandates the validation of every claim against primary sources (code context, official docs, reproduced behavior) rather than internal summaries or rules.
  • Capability inventory: The skill directs the agent to execute a wide variety of SAST, SCA, and secret scanning tools listed in the tool matrix of rules/01-audit-methodology.md.
  • Sanitization: Operating Principle 7 requires the agent to re-read artifacts directly from the source to prevent reliance on potentially poisoned session summaries.
  • [EXTERNAL_DOWNLOADS]: The skill refers to local initialization scripts, scripts/init-gates.sh and scripts/gen-agents-md.sh, to be executed for repositories lacking security gates. It also provides a link to report issues at a GitHub repository owned by the skill author.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 10:01 PM
Security Audit — agent-trust-hub — sota