secret-scanning

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the agent to process and scan code changes, establishing a surface for indirect prompt injection if scanned files contain malicious instructions.
  • Ingestion points: Code files and Git history.
  • Boundary markers: Absent.
  • Capability inventory: Git commands and run_secret_scanning tool.
  • Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: Suggests installing git-filter-repo via pip to facilitate cleaning secrets from Git history.
  • [EXTERNAL_DOWNLOADS]: References the installation of the official GitHub advanced-security@copilot-plugins plugin for enhanced scanning capabilities.
  • [COMMAND_EXECUTION]: Details standard Git operations such as rebase and commit to manage and remediate exposed credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:36 AM
Security Audit — agent-trust-hub — secret-scanning