code-hardcode-audit
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto orchestrate several security scanners, including Ruff, Semgrep, Gitleaks, Bandit, TruffleHog, Whispers, ast-grep, and jscpd. The implementation uses argument lists to prevent command injection from file paths. - [EXTERNAL_DOWNLOADS]: The skill relies on established third-party security tools and provides instructions to install them via official package registries and well-known installation methods like Homebrew, Cargo, NPM, and PyPI.
- [INDIRECT_PROMPT_INJECTION]: Auditing arbitrary code directories introduces an attack surface where malicious comments or strings in the scanned code could attempt to influence the agent's summary report.
- Ingestion points: Source code files in the user-specified target directory processed by
scripts/audit_hardcodes.py. - Boundary markers: None identified in the orchestrator scripts.
- Capability inventory: The skill has capabilities for file system read access and command execution of various security scanners.
- Sanitization: Scanner outputs are aggregated without specific filtering for embedded instructions targeting the LLM.
Audit Metadata