source-aware-sast

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple security-related command-line tools including semgrep, gitleaks, trufflehog, trivy, and ast-grep to perform repository analysis.- [COMMAND_EXECUTION]: An embedded Python script is used to parse Semgrep results and generate a list of target files for further structural analysis, facilitating an automated audit pipeline.- [EXTERNAL_DOWNLOADS]: The scanners may fetch rulesets or vulnerability databases from their official registries (e.g., Semgrep Registry), which is standard behavior for these tools.- [SAFE]: No evidence of data exfiltration, credential theft, or unauthorized persistence mechanisms was detected. The skill's operations are confined to the local workspace and intended for security analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 08:57 AM
Security Audit — agent-trust-hub — source-aware-sast