security-audit

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: A static detector flagged a potential concern in references/skills.md regarding 'unrestricted mode'. However, manual review confirms this is a false positive. The text describes security risks to watch for (e.g., 'disable safety checks') during an audit rather than attempting to perform an injection or bypass guidelines.
  • [EXTERNAL_DOWNLOADS]: The skill references established security resources for vulnerability verification, including osv.dev, pkg.go.dev, ruby-lang.org, and cisa.gov. These are well-known, trusted services used for legitimate security research.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard security tools such as govulncheck, trivy, and shellcheck via repository-defined make targets. It explicitly requires the agent to obtain user permission before running any scanner that requires network access or authentication.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:14 PM
Security Audit — agent-trust-hub — security-audit