open-source-checker
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing various shell commands and security tools such as git, grep, gitleaks, and trufflehog to perform its repository audit functions across all refs and history.\n- [EXTERNAL_DOWNLOADS]: The audit process utilizes
bunxto run thelicense-checkerutility and recommends other ecosystem-specific tools likepip-licenses,cargo-license, andgo-licenseswhich are retrieved from official package registries.\n- [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface as it is designed to ingest and analyze the entire history and content of a repository, which may contain untrusted third-party code or malicious instructions targeting the agent.\n - Ingestion points: The audit passes defined in
SKILL.mdandreferences/full-guide.mddescribe processes for reading all files, commit messages, and metadata in the target repository's git history.\n - Boundary markers: The instructions do not currently include explicit markers or warnings to the agent to ignore instructions found within the audited codebase.\n
- Capability inventory: The skill uses subprocess calls to execute git commands, grep, and various scanners across the full scope of the repository.\n
- Sanitization: The skill does not describe any specific sanitization or escaping of the audited content before it is processed by the agent.
Audit Metadata