git-security

Pass

Audited by Gen Agent Trust Hub on Mar 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The scan.js script uses child_process.execSync to run git diff --cached --name-only. This command is used to retrieve the list of files staged in the repository so they can be scanned for secrets, which is a legitimate part of the skill's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 1, 2026, 05:11 AM