find-security-vulnerabilities-in-code

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute the strix command-line utility to perform security reviews and exploitation tests.
  • Evidence: Commands such as strix -n -t ./ --scan-mode standard and strix -n -t https://github.com/org/app are provided as standard usage examples in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of source code repositories.
  • Ingestion points: The tool reads source code from the local filesystem (./) or remote Git repositories (e.g., https://github.com/org/app).
  • Boundary markers: There are no explicit delimiters or specific instructions to the agent to ignore potential prompts embedded within the analyzed source code.
  • Capability inventory: The agent has the capability to execute the strix CLI tool and read various report files (markdown, JSON, CSV, SARIF) from the strix_runs/ directory.
  • Sanitization: No specific sanitization or filtering of the source code content is described before the agent processes the tool's findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 02:07 AM
Security Audit — agent-trust-hub — find-security-vulnerabilities-in-code