security-audit-toolkit

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Provides transparent bash scripts and command-line pipelines for auditing project security. These include a pre-commit hook for secret detection and a full project audit script (security-audit.sh) that automates checks for vulnerabilities and misconfigurations. These scripts use standard system tools like grep, find, and git to perform their stated functions.
  • [EXTERNAL_DOWNLOADS]: References and encourages the use of well-known security tools from trusted technology providers, such as Aqua Security's Trivy, pip-audit, cargo-audit, and Go's govulncheck. These tools are standard for security practitioners and are used here to enhance the skill's auditing capabilities.
  • [DATA_EXPOSURE]: Includes instructions for locating sensitive files (e.g., .env, private keys, SSH configurations) and auditing their file permissions. This activity is restricted to local identification and verification of security best practices, with no evidence of unauthorized data access or exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:05 AM
Security Audit — agent-trust-hub — security-audit-toolkit