vuln-patterns-core
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides multiple
grepcommands and a bash script intended to be executed on the local filesystem to identify security vulnerabilities. These tools are consistent with the skill's purpose as a vulnerability scanner. - [SAFE]: The regular expressions for detecting hardcoded secrets and private keys are standard security patterns. The skill does not perform any network operations, exfiltration, or obfuscation.
- [COMMAND_EXECUTION]: As a security auditing tool, the skill has an ingestion surface for indirect prompt injection because it processes content from the local codebase through shell commands without explicit boundary markers or sanitization; however, this risk is inherent to its primary function and is not indicative of malicious design.
Audit Metadata