semgrep-rule-variant-creator
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill accepts existing Semgrep rule content or file paths as primary input for transformation. This ingestion point lacks explicit boundary markers or sanitization logic, creating a surface for indirect prompt injection. A malicious rule could contain instructions designed to influence the agent's output or actions during the porting cycle. Evidence includes: ingestion of untrusted YAML content in SKILL.md; absence of input delimiters; and capabilities to execute Semgrep CLI commands for validation and testing.
- [EXTERNAL_DOWNLOADS]: The skill provides links to official Semgrep documentation and the Trail of Bits AppSec guide. These are trusted technical resources used for legitimate reference and do not involve the automated download of executable code or sensitive data exfiltration.
Audit Metadata