backend-security-coder

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of role-play, jailbreak, or system prompt extraction instructions. The skill focuses on legitimate security coaching and implementation tasks without attempting to override safety filters.
  • [DATA_EXFILTRATION]: No network operations (curl, wget, etc.) or access to sensitive file paths (e.g., .ssh, .aws) were identified. The instructions focus on creating secure code rather than accessing local secrets.
  • [COMMAND_EXECUTION]: No shell command execution or persistence mechanisms were found. The skill does not instruct the agent to execute code on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill does not attempt to download external scripts or packages. It references a local resource file ('resources/implementation-playbook.md'), which is a standard pattern for skill-internal documentation.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or credentials were found in the instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 09:54 AM
Security Audit — agent-trust-hub — backend-security-coder