bughunter

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses local shell commands including git, find, and sed to scope the analysis and identify relevant source files.
  • [DATA_EXPOSURE]: The workflow involves searching for sensitive data such as hardcoded API keys and secrets (e.g., AWS keys, GitHub tokens) within the project. This is a primary feature of the bug-hunting utility and the results are reported back to the user without any external exfiltration detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data by reading the content of files within the user's codebase. This creates a surface for indirect prompt injection where malicious instructions embedded in code comments or strings could attempt to manipulate the agent's reporting or behavior. This risk is mitigated by the instruction to 'verify each finding by reading surrounding context' and is typical for static analysis tools.
  • [SAFE]: The skill follows security best practices for a local auditing tool, focusing on identification and reporting without attempting to modify the system or communicate with external servers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:12 PM