security-implementation-guide
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely composed of documentation and reference code snippets. There are no executable scripts, binaries, or configuration files that would perform actions on the host system beyond providing information to the user.
- [COMMAND_EXECUTION]: Static analysis identified the destructive command pattern
rm -rf /withinreferences/owasp-top-10.md. A contextual review confirms this string is part of an illustrative example documenting how command injection attacks occur. It is correctly labeled as a vulnerability to avoid and is not used in an executable context. - [CREDENTIALS_UNSAFE]: The skill demonstrates secure handling of sensitive data. Code examples for password hashing and encryption utilize standard libraries (bcrypt, crypto) and properly reference environment variables (e.g.,
process.env.ENCRYPTION_KEY) rather than hardcoding secrets. - [EXTERNAL_DOWNLOADS]: The documentation mentions third-party security tools such as Snyk and NPM for auditing. These are documented as recommended tools for the user's development workflow and do not involve the skill itself performing unauthorized remote downloads.
Audit Metadata