setup-auditor
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructions direct the agent to scan and process highly sensitive system files, including
~/.ssh/id_rsa,~/.ssh/id_ed25519,~/.aws/credentials, and various environment files (.env). Although this is part of its stated purpose as a security auditor, accessing these files exposes the user's private keys and primary credentials to the agent context. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple external files during the audit process. Because the skill is granted
file-writepermissions to generate reports and configuration templates, it presents an attack surface where malicious content within the audited files could potentially influence the agent to write unauthorized data to the workspace or misrepresent the audit results. - Ingestion points: Files targeted in the
Credential Scanstep, such as~/.ssh/config,~/.aws/credentials, and.envfiles located in the workspace, as specified inSKILL.md. - Boundary markers: The skill lacks explicit delimiters or instructions for the agent to differentiate between the data being audited and its own operational instructions.
- Capability inventory: The skill possesses
file-readandfile-writepermissions according to its YAML frontmatter, allowing it to ingest sensitive data and modify the filesystem. - Sanitization: The skill includes clear instructions to mask and truncate secret values in the generated report to prevent the exposure of full credentials in the audit output.
Audit Metadata