credential-scanner
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration files and source code files which are untrusted inputs, creating an indirect prompt injection vulnerability surface where a file could contain instructions to manipulate the agent's behavior.
- Ingestion points: Project files such as
.env,docker-compose.yml,config.json, and source code files read from the current workspace during scanning. - Boundary markers: Absent; the instructions do not require the agent to wrap file content in specific delimiters or explicitly ignore text commands within files.
- Capability inventory: File reading is enabled (
file-read: true), but the skill has no file writing (file-write: false), network access (network: false), or shell capabilities (shell: false). - Sanitization: Found secret values are successfully masked using
████████to prevent direct exposure, but no sanitization or parsing logic is specified to filter or neutralize natural language prompts within the text.
Audit Metadata