backend-security-coder
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of role-play, jailbreak, or system prompt extraction instructions. The skill focuses on legitimate security coaching and implementation tasks without attempting to override safety filters.
- [DATA_EXFILTRATION]: No network operations (curl, wget, etc.) or access to sensitive file paths (e.g., .ssh, .aws) were identified. The instructions focus on creating secure code rather than accessing local secrets.
- [COMMAND_EXECUTION]: No shell command execution or persistence mechanisms were found. The skill does not instruct the agent to execute code on the host system.
- [EXTERNAL_DOWNLOADS]: The skill does not attempt to download external scripts or packages. It references a local resource file ('resources/implementation-playbook.md'), which is a standard pattern for skill-internal documentation.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or credentials were found in the instructions or metadata.
Audit Metadata