secret-scanning
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to process and scan code changes, establishing a surface for indirect prompt injection if scanned files contain malicious instructions.
- Ingestion points: Code files and Git history.
- Boundary markers: Absent.
- Capability inventory: Git commands and run_secret_scanning tool.
- Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: Suggests installing git-filter-repo via pip to facilitate cleaning secrets from Git history.
- [EXTERNAL_DOWNLOADS]: References the installation of the official GitHub advanced-security@copilot-plugins plugin for enhanced scanning capabilities.
- [COMMAND_EXECUTION]: Details standard Git operations such as rebase and commit to manage and remediate exposed credentials.
Audit Metadata