audit-security

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill's instructions and reference files align with its stated purpose of providing a security audit methodology.
  • [COMMAND_EXECUTION]: The skill uses Bash tools restricted to git and grep operations as defined in the allowed-tools metadata. This is a standard requirement for repository auditing and does not involve arbitrary or dangerous command execution.
  • [DATA_EXPOSURE]: The skill is designed to find sensitive data such as API keys and tracked .env files within the repository's history and current files. While this involves handling sensitive information, the skill does not contain instructions to transmit this data to external or untrusted destinations.
  • [INDIRECT_PROMPT_INJECTION]: As an auditing tool, the skill has an inherent attack surface because it processes untrusted code and data from the repository being scanned. However, the instructions include a rigorous triage process (real, false-positive, needs-review) which requires the agent to reason about findings rather than blindly executing instructions found in the scanned files. No specific exploitation patterns for this surface were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 02:12 AM
Security Audit — agent-trust-hub — audit-security