audit-security
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected. The skill's instructions and reference files align with its stated purpose of providing a security audit methodology.
- [COMMAND_EXECUTION]: The skill uses
Bashtools restricted togitandgrepoperations as defined in theallowed-toolsmetadata. This is a standard requirement for repository auditing and does not involve arbitrary or dangerous command execution. - [DATA_EXPOSURE]: The skill is designed to find sensitive data such as API keys and tracked
.envfiles within the repository's history and current files. While this involves handling sensitive information, the skill does not contain instructions to transmit this data to external or untrusted destinations. - [INDIRECT_PROMPT_INJECTION]: As an auditing tool, the skill has an inherent attack surface because it processes untrusted code and data from the repository being scanned. However, the instructions include a rigorous triage process (real, false-positive, needs-review) which requires the agent to reason about findings rather than blindly executing instructions found in the scanned files. No specific exploitation patterns for this surface were identified.
Audit Metadata