secure-by-default

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill executes a local shell script (scripts/scan_redflags.sh) to perform heuristic static analysis on the codebase. This script uses grep to locate potential secrets and risky coding patterns, which is consistent with the skill's primary purpose.
  • [SAFE]: The skill provides comprehensive security checklists for Next.js and React Native, focusing on trust boundaries, authentication, and secure storage.
  • [SAFE]: The skill contains an indirect prompt injection surface because it is designed to ingest and analyze untrusted code from a repository. Ingestion points: Repository source code reviewed by the agent as instructed in SKILL.md. Boundary markers: Not specified in instructions. Capability inventory: Execution of analysis scripts via shell. Sanitization: None; the skill relies on the agent's interpretation of findings. This surface is inherent to its intended function as a code analysis tool.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 04:01 PM
Security Audit — agent-trust-hub — secure-by-default