source-code-scanning
Pass
Audited by Gen Agent Trust Hub on May 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a documentation-focused utility that provides instructions for security auditing. Findings related to dangerous code patterns (such as
evalorexec) inreference/language-patterns.mdandreference/malicious-code.mdare false positives; these files contain reference examples for the agent to identify during its scanning process. - [SAFE]: All external tools and dependencies recommended (e.g., Semgrep, Bandit, TruffleHog, Snyk, Gitleaks) are reputable, well-known security utilities from trusted software ecosystems and organizations.
- [SAFE]: The skill includes security best practices, such as warnings against executing untrusted code and instructions for rotating compromised secrets.
- [SAFE]: The potential for indirect prompt injection via the processing of untrusted source code is an inherent aspect of the skill's primary function (security auditing) and is addressed through a structured, tool-based analysis workflow rather than blind execution of input.
Audit Metadata