sca-audit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted project dependency manifests (e.g., package.json, requirements.txt, go.mod), which could contain malicious data designed to influence the agent's behavior.
  • Ingestion points: Dependency manifests and lockfiles from the scanned project.
  • Boundary markers: No specific boundary markers or 'ignore' instructions are provided to the agent for manifest content.
  • Capability inventory: File system access (reading manifests) and shell command execution (running scanners).
  • Sanitization: There is no instruction to sanitize or validate the manifest content before it is parsed by the agent or scanner tools.
  • [COMMAND_EXECUTION]: The skill directs the agent to execute several command-line vulnerability scanners (osv-scanner, npm audit, pip-audit, govulncheck, and trivy). These are legitimate tools for the skill's purpose but involve shell execution capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:34 PM
Security Audit — agent-trust-hub — sca-audit