locate-implementation

Warn

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructs the agent to search sensitive environment files (e.g., .env, .env.local) when looking for configuration keys, which could lead to the exposure of credentials stored in the environment.
  • [COMMAND_EXECUTION]: The skill utilizes shell-based grep commands to perform search operations across the codebase.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data to confirm relevance, creating an indirect injection surface.
  • Ingestion points: Codebase files and grep results (SKILL.md).
  • Boundary markers: None present.
  • Capability inventory: Shell command execution (grep).
  • Sanitization: None present.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 16, 2026, 11:13 AM
Security Audit — agent-trust-hub — locate-implementation