find-security-vulnerabilities-in-code
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the
strixcommand-line utility to perform security reviews and exploitation tests. - Evidence: Commands such as
strix -n -t ./ --scan-mode standardandstrix -n -t https://github.com/org/appare provided as standard usage examples inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of source code repositories.
- Ingestion points: The tool reads source code from the local filesystem (
./) or remote Git repositories (e.g.,https://github.com/org/app). - Boundary markers: There are no explicit delimiters or specific instructions to the agent to ignore potential prompts embedded within the analyzed source code.
- Capability inventory: The agent has the capability to execute the
strixCLI tool and read various report files (markdown, JSON, CSV, SARIF) from thestrix_runs/directory. - Sanitization: No specific sanitization or filtering of the source code content is described before the agent processes the tool's findings.
Audit Metadata