file-search

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from the local filesystem through various search tools including ripgrep, ast-grep, and ripgrep-all. \n
  • Ingestion points: Text and structural search results from files in the analyzed codebase. \n
  • Boundary markers: Absent; there are no specific instructions for the agent to use delimiters or ignore embedded instructions within search results. \n
  • Capability inventory: The skill utilizes the Bash tool (restricted to specific search utilities), Read, Glob, and Grep. \n
  • Sanitization: None; search output is processed directly by the agent to build context. \n- [EXTERNAL_DOWNLOADS]: The skill documents the use of semgrep with the --config=auto flag, which retrieves rule packs from the Semgrep Registry. This targets a well-known security service and is part of the tool's standard functionality. \n- [SAFE]: All provided search patterns and examples in the reference files are consistent with the skill's primary purpose of codebase exploration and security auditing. The use of Bash is appropriately scoped to a set of specific search binaries, following the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 05:24 PM