sast-fileupload
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a standard security auditing tool designed to perform static analysis on source code to identify insecure file upload patterns.
- [SAFE]: The skill instructions define a clear, non-malicious workflow using subagents to process local codebase information and generate reports in markdown format.
- [SAFE]: No evidence of prompt injection, data exfiltration, obfuscation, or unauthorized remote code execution was found in the skill content.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential attack surface by ingesting untrusted source code during its discovery and verification phases. However, this is an inherent part of its functionality as a security tool, and the structured nature of its phases (discovery, batched verification, and merging) provides internal controls against accidental obedience to instructions embedded in the analyzed data.
Audit Metadata