security-audit

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted codebase data, which presents an inherent surface for indirect prompt injection. Malicious content within the audited files could theoretically attempt to manipulate the agent's audit summary, though this is a standard risk for auditing tools.
  • [COMMAND_EXECUTION]: The skill instructs the agent to check for and execute various security tools (gitleaks, semgrep, trivy, govulncheck) via the shell. These operations are limited to scanning the local project directory and are essential for the skill's primary function.
  • [SAFE]: The skill is well-structured, provides clear security guidance, and does not contain any obfuscated code, hardcoded credentials, or unauthorized network activity. It promotes security best practices such as secret rotation and dependency verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:27 AM
Security Audit — agent-trust-hub — security-audit