security-hardening-wizard
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute various shell commands for dependency auditing and static analysis (e.g.,
npm audit,pip-audit,gitleaks,trufflehog). These commands are standard for the stated purpose of security hardening. The skill includes specific instructions to verify tools and avoid executing unverified scripts, following best practices for environment interaction.- [EXTERNAL_DOWNLOADS]: The skill involves downloading and installing security tools from official registries like npm and PyPI. These are recognized as well-known and trusted services. The instructions include a 'Trust boundaries' section that explicitly restricts downloads to official sources and verified GitHub releases, which mitigates supply chain risks associated with third-party tools.- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and analyze every file in a project, including source code, markdown, and documentation. This creates a potential vulnerability surface where malicious instructions embedded in a project's files (e.g., a README or CI config) could attempt to override the agent's behavior during the audit process.\n - Ingestion points: Step 1 (Full file inventory) and Step 3 (Manual review) involve reading all project files into the agent's context.\n
- Boundary markers: The instructions lack explicit delimiters or specific warnings to ignore natural language instructions found within the processed files.\n
- Capability inventory: The agent has extensive file-writing capabilities (Step 4 and 5) and shell execution capabilities (Step 2 and 7) which could be targeted by successful injection.\n
- Sanitization: No specific filtering or sanitization mechanism is described for handling external file content.
Audit Metadata