sast-fileupload

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a standard security auditing tool designed to perform static analysis on source code to identify insecure file upload patterns.
  • [SAFE]: The skill instructions define a clear, non-malicious workflow using subagents to process local codebase information and generate reports in markdown format.
  • [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or unauthorized remote code execution was found in the skill content.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting untrusted source code during its discovery and verification phases. However, this is an inherent part of its functionality as a security tool, and the structured nature of its phases (discovery, batched verification, and merging) provides internal controls against accidental obedience to instructions embedded in the analyzed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:34 AM
Security Audit — agent-trust-hub — sast-fileupload