vuln-defectdojo

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the DefectDojo platform from its official GitHub repository and references established security organizations such as OWASP. These are well-known, trusted sources consistent with the skill's purpose.
  • [COMMAND_EXECUTION]: The documentation and scripts involve executing standard shell commands for Docker container management, repository cloning, and running the provided Python integration script. All commands are routine for a development and security operations workflow.
  • [CREDENTIALS_UNSAFE]: The skill correctly manages sensitive information such as API keys by using environment variables, command-line arguments, and placeholders. No hardcoded secrets or unsafe credential management practices were detected.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were found. The skill operates as a transparent utility for managing vulnerability data in a user-controlled environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:00 AM
Security Audit — agent-trust-hub — vuln-defectdojo