secure-by-default
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill executes a local shell script (
scripts/scan_redflags.sh) to perform heuristic static analysis on the codebase. This script usesgrepto locate potential secrets and risky coding patterns, which is consistent with the skill's primary purpose. - [SAFE]: The skill provides comprehensive security checklists for Next.js and React Native, focusing on trust boundaries, authentication, and secure storage.
- [SAFE]: The skill contains an indirect prompt injection surface because it is designed to ingest and analyze untrusted code from a repository. Ingestion points: Repository source code reviewed by the agent as instructed in
SKILL.md. Boundary markers: Not specified in instructions. Capability inventory: Execution of analysis scripts via shell. Sanitization: None; the skill relies on the agent's interpretation of findings. This surface is inherent to its intended function as a code analysis tool.
Audit Metadata