scan-code

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [Command Execution]: The skill utilizes local security tools to audit source code and dependencies. These operations are restricted to verified Power Pages project directories using validation scripts, ensuring that command execution is focused on intended project targets.
  • [Secret Management]: A notable security consideration in this skill is the automated masking of credentials. Both the instructions to the agent and the supporting transformation scripts are designed to identify and obscure sensitive information, such as API keys and tokens, preventing their exposure in summaries, logs, or reports.
  • [Dynamic Context Injection]: The skill performs an automated version check upon loading using a internal script. This is a standard utility pattern used to ensure the skill environment is up-to-date and does not involve processing untrusted input at that stage.
  • [Untrusted Data Processing]: As the skill is designed to analyze project source code and dependency metadata, it inherently processes external data. It addresses the potential for indirect prompt injection by providing explicit warnings to the user about data processing terms and by utilizing structured local tools for the primary scanning logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 09:40 AM
Security Audit — agent-trust-hub — scan-code