compliance-checker
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill instructions and search patterns explicitly direct the agent to identify and access highly sensitive files and data categories within the audit scope, including environment variables (.env), secrets configuration, credentials, and cryptographic keys such as *.key and *.pem files (Evidence: references/scan-patterns.md). This access is a core component of the auditing functionality but involves exposure of sensitive credentials to the agent context.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from target project files and documentation (Ingestion points: SKILL.md, Phases 1 and 2). It has the capability to execute shell commands and write files (Capability inventory: Bash and Write tools). There are no instructions for using boundary markers to isolate untrusted data (Boundary markers: Absent). The skill does not define sanitization or filtering procedures for the codebase snippets processed by the agent (Sanitization: Absent).
Audit Metadata