skills/paniolo-ai/scan/paniolo-scan/Gen Agent Trust Hub

paniolo-scan

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes npx @paniolo/cli scan to generate a diagnostic report of the repository's AI harness. The command is used in a deterministic, read-only mode for scanning.
  • [EXTERNAL_DOWNLOADS]: The skill invokes the @paniolo/cli package via npx, which involves downloading the package from the NPM registry. This package is an official vendor resource belonging to 'paniolo-ai'.
  • [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection as it processes external data to drive file modifications.
  • Ingestion points: The agent reads and processes JSON output from the @paniolo/cli tool (SKILL.md).
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are used when interpreting the tool's output.
  • Capability inventory: The agent has the capability to write and edit files in the working tree to remediate findings (SKILL.md).
  • Sanitization: The instructions do not specify sanitization or validation of the findings provided by the CLI tool before the agent performs file edits.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 04:54 PM
Security Audit — agent-trust-hub — paniolo-scan