security-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands for industry-standard security tools such as nmap, sqlmap, gitleaks, and semgrep. These are intended to be executed via the Bash tool to perform authorized security assessments and reconnaissance.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including source code, infrastructure manifests, and logs, which is a standard requirement for a security auditor persona.
  • Ingestion points: The agent utilizes Read, Grep, and Glob tools to access project files for analysis across all reference documents.
  • Boundary markers: The instructions do not mandate specific delimiters to isolate analyzed code from agent instructions, but the workflow emphasizes manual validation and confirmation of findings.
  • Capability inventory: The agent has access to Bash, enabling file system access and network interactions required for security scanning and penetration testing.
  • Sanitization: The instructions focus on identifying vulnerabilities within the analyzed content rather than executing the content, though no specific sanitization protocols are defined for the ingestion process.
  • [PRIVILEGE_ESCALATION]: Documentation in references/penetration-testing.md provides instructions for identifying privilege escalation vectors in target systems, such as checking for SUID binaries and insecure sudo configurations. These are diagnostic checks intended for auditing target environments and do not represent attempts to escalate the agent's own execution privileges.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — security-reviewer