vulnerability-scanner

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • NO_CODE (SAFE): The skill documentation in SKILL.md references a Python script at scripts/security_scan.py for automated validation. This file was not included in the provided skill package, meaning the automated functionality is not available.\n- Indirect Prompt Injection (SAFE): The skill is designed to ingest and analyze untrusted external project data, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Project code and configuration files read via Read, Glob, and Grep tools.\n
  • Boundary markers: No specific delimiters or instructions for the agent to ignore embedded instructions in the scanned data are provided.\n
  • Capability inventory: The skill allows the use of Bash, Read, Glob, and Grep tools.\n
  • Sanitization: No input validation or sanitization logic is present in the markdown instructions. The risk is inherent to the use-case of a security scanner and no malicious code is currently present to exploit this surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:12 PM