setup-auditor

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructions direct the agent to scan and process highly sensitive system files, including ~/.ssh/id_rsa, ~/.ssh/id_ed25519, ~/.aws/credentials, and various environment files (.env). Although this is part of its stated purpose as a security auditor, accessing these files exposes the user's private keys and primary credentials to the agent context.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple external files during the audit process. Because the skill is granted file-write permissions to generate reports and configuration templates, it presents an attack surface where malicious content within the audited files could potentially influence the agent to write unauthorized data to the workspace or misrepresent the audit results.
  • Ingestion points: Files targeted in the Credential Scan step, such as ~/.ssh/config, ~/.aws/credentials, and .env files located in the workspace, as specified in SKILL.md.
  • Boundary markers: The skill lacks explicit delimiters or instructions for the agent to differentiate between the data being audited and its own operational instructions.
  • Capability inventory: The skill possesses file-read and file-write permissions according to its YAML frontmatter, allowing it to ingest sensitive data and modify the filesystem.
  • Sanitization: The skill includes clear instructions to mask and truncate secret values in the generated report to prevent the exposure of full credentials in the audit output.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:43 AM
Security Audit — agent-trust-hub — setup-auditor