git-security
Pass
Audited by Gen Agent Trust Hub on Mar 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scan.jsscript useschild_process.execSyncto rungit diff --cached --name-only. This command is used to retrieve the list of files staged in the repository so they can be scanned for secrets, which is a legitimate part of the skill's core functionality.
Audit Metadata