vuln-defectdojo
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the DefectDojo platform from its official GitHub repository and references established security organizations such as OWASP. These are well-known, trusted sources consistent with the skill's purpose.
- [COMMAND_EXECUTION]: The documentation and scripts involve executing standard shell commands for Docker container management, repository cloning, and running the provided Python integration script. All commands are routine for a development and security operations workflow.
- [CREDENTIALS_UNSAFE]: The skill correctly manages sensitive information such as API keys by using environment variables, command-line arguments, and placeholders. No hardcoded secrets or unsafe credential management practices were detected.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were found. The skill operates as a transparent utility for managing vulnerability data in a user-controlled environment.
Audit Metadata