vulnerability-scanner
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFE
Full Analysis
- Security Auditing Principles (SAFE): The skill contains high-quality educational content regarding threat modeling, OWASP Top 10 (2025), and supply chain security. No malicious instructions, obfuscation, or hardcoded credentials were found in the provided files.\n- Indirect Prompt Injection Surface (LOW): The skill is intended to analyze external codebases, which are untrusted data sources. This is an inherent risk for security tools, as malicious code could attempt to manipulate the scanner's output or logic.\n
- Ingestion points: File analysis at
<project_path>usingRead,Glob, andGreptools.\n - Boundary markers: None are present in the provided markdown files to isolate scanned code from agent instructions.\n
- Capability inventory: The skill has permission to use
Bashandpython, which are necessary for the referenced (though not provided)security_scan.pyscript.\n - Sanitization: No specific input sanitization or validation logic is documented in the reference files.
Audit Metadata