vuln-patterns-core

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides multiple grep commands and a bash script intended to be executed on the local filesystem to identify security vulnerabilities. These tools are consistent with the skill's purpose as a vulnerability scanner.
  • [SAFE]: The regular expressions for detecting hardcoded secrets and private keys are standard security patterns. The skill does not perform any network operations, exfiltration, or obfuscation.
  • [COMMAND_EXECUTION]: As a security auditing tool, the skill has an ingestion surface for indirect prompt injection because it processes content from the local codebase through shell commands without explicit boundary markers or sanitization; however, this risk is inherent to its primary function and is not indicative of malicious design.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 01:18 AM
Security Audit — agent-trust-hub — vuln-patterns-core