code-hardcode-audit

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to orchestrate several security scanners, including Ruff, Semgrep, Gitleaks, Bandit, TruffleHog, Whispers, ast-grep, and jscpd. The implementation uses argument lists to prevent command injection from file paths.
  • [EXTERNAL_DOWNLOADS]: The skill relies on established third-party security tools and provides instructions to install them via official package registries and well-known installation methods like Homebrew, Cargo, NPM, and PyPI.
  • [INDIRECT_PROMPT_INJECTION]: Auditing arbitrary code directories introduces an attack surface where malicious comments or strings in the scanned code could attempt to influence the agent's summary report.
  • Ingestion points: Source code files in the user-specified target directory processed by scripts/audit_hardcodes.py.
  • Boundary markers: None identified in the orchestrator scripts.
  • Capability inventory: The skill has capabilities for file system read access and command execution of various security scanners.
  • Sanitization: Scanner outputs are aggregated without specific filtering for embedded instructions targeting the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 04:07 PM
Security Audit — agent-trust-hub — code-hardcode-audit