cybersecurity
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation references the official GitHub repository for Gitleaks (https://github.com/gitleaks/gitleaks) as a recommended tool for secrets management and pre-commit scanning.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and review user-provided code and security-related inputs, creating a surface for indirect prompt injection attacks. 1. Ingestion points: User-provided code snippets or security queries processed by the agent using the instructions in SKILL.md. 2. Boundary markers: The skill does not specify explicit boundary markers or ignore instructions to delimit user-provided content. 3. Capability inventory: The skill acts purely as an advisor and does not have capabilities to execute shell commands, perform network operations, or write to the file system. 4. Sanitization: No explicit sanitization or filtering logic is defined for the external content it processes.
Audit Metadata