cosmos-vulnerability-scanner

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted codebases for security analysis, which is its primary function. While this creates an attack surface, the risk is mitigated by the skill's specific focus on consensus-critical vulnerability patterns. * Ingestion points: Target codebase files are read using the Grep, Glob, and Read tools in the Discovery and Parallel Scan phases. * Boundary markers: The skill does not explicitly use delimiters when interpolating untrusted file content into subagent prompts. * Capability inventory: The agent can write findings to the local filesystem using the Write tool. * Sanitization: No explicit sanitization of external code content is performed before analysis.- [SAFE]: The skill exhibits no malicious behaviors. All external references point to reputable security documentation and advisories. The tools used (pattern matching and local file writing) are appropriate for the tool's stated purpose of providing security audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:09 AM
Security Audit — agent-trust-hub — cosmos-vulnerability-scanner