security-audit
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: A static detector flagged a potential concern in
references/skills.mdregarding 'unrestricted mode'. However, manual review confirms this is a false positive. The text describes security risks to watch for (e.g., 'disable safety checks') during an audit rather than attempting to perform an injection or bypass guidelines. - [EXTERNAL_DOWNLOADS]: The skill references established security resources for vulnerability verification, including
osv.dev,pkg.go.dev,ruby-lang.org, andcisa.gov. These are well-known, trusted services used for legitimate security research. - [COMMAND_EXECUTION]: The skill instructs the agent to use standard security tools such as
govulncheck,trivy, andshellcheckvia repository-definedmaketargets. It explicitly requires the agent to obtain user permission before running any scanner that requires network access or authentication.
Audit Metadata