credential-scanner

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration files and source code files which are untrusted inputs, creating an indirect prompt injection vulnerability surface where a file could contain instructions to manipulate the agent's behavior.
  • Ingestion points: Project files such as .env, docker-compose.yml, config.json, and source code files read from the current workspace during scanning.
  • Boundary markers: Absent; the instructions do not require the agent to wrap file content in specific delimiters or explicitly ignore text commands within files.
  • Capability inventory: File reading is enabled (file-read: true), but the skill has no file writing (file-write: false), network access (network: false), or shell capabilities (shell: false).
  • Sanitization: Found secret values are successfully masked using ████████ to prevent direct exposure, but no sanitization or parsing logic is specified to filter or neutralize natural language prompts within the text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:43 AM
Security Audit — agent-trust-hub — credential-scanner