security-testing
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is focused on providing educational and functional templates for application security testing. No evidence of malicious intent was found across the metadata or referenced documents.\n- [EXTERNAL_DOWNLOADS]: References well-known and trusted security resources, specifically the official 'zaproxy/action-baseline' GitHub Action for automated security scans.\n- [COMMAND_EXECUTION]: Contains standard shell commands for development workflows, including 'npm audit' for Node.js dependency checks and 'pip install safety' for Python vulnerability scanning.\n- [INDIRECT_PROMPT_INJECTION]: While the skill contains strings for SQL injection and XSS testing in 'references/sql-injection-testing.md' and 'references/xss-testing.md', these are static test payloads designed for vulnerability verification. There is no automated ingestion of untrusted data from external network sources that could trigger an injection attack against the agent itself.
Audit Metadata