sast-configuration

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official repositories and components for well-known security tools, including Semgrep (returntocorp/semgrep) and the CodeQL CLI extension. These are established resources from recognized technology providers.
  • [COMMAND_EXECUTION]: Provides standard commands for installing and initializing security tools, such as 'pip install semgrep', 'docker run' for SonarQube, and GitHub CLI commands for CodeQL. The referenced local script './scripts/run-sast.sh' is presented as a template for automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the setup of scanners that ingest external source code for analysis. 1. Ingestion points: Source code repositories analyzed by Semgrep, SonarQube, or CodeQL. 2. Boundary markers: Not specified in the configuration examples. 3. Capability inventory: Local command execution for tool installation and scan execution. 4. Sanitization: Not explicitly addressed in the baseline templates. This represents a standard attack surface for automated security testing tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 03:15 PM
Security Audit — agent-trust-hub — sast-configuration