source-aware-sast
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple security-related command-line tools including
semgrep,gitleaks,trufflehog,trivy, andast-grepto perform repository analysis.- [COMMAND_EXECUTION]: An embedded Python script is used to parse Semgrep results and generate a list of target files for further structural analysis, facilitating an automated audit pipeline.- [EXTERNAL_DOWNLOADS]: The scanners may fetch rulesets or vulnerability databases from their official registries (e.g., Semgrep Registry), which is standard behavior for these tools.- [SAFE]: No evidence of data exfiltration, credential theft, or unauthorized persistence mechanisms was detected. The skill's operations are confined to the local workspace and intended for security analysis.
Audit Metadata