awesome-claude-code-security-compliance-suite

Pass

Audited by Gen Agent Trust Hub on May 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a prompt and documentation library, guiding the AI agent to perform security tasks without containing any malicious executable logic.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions to clone its own repository from GitHub (github.com/sparkfinderoven/r01-hesreallyhim-awesome-claude-code-security.git) to a local directory. This is the standard method for installing local skills in the supported environment.\n- [EXTERNAL_DOWNLOADS]: The documentation references official GitHub repositories for established security tools such as Yelp/detect-secrets and gitleaks/gitleaks. These are well-known industry resources used for secret detection.\n- [COMMAND_EXECUTION]: The documentation includes example commands (e.g., /owasp-scan, /dep-cve) and shell snippets for installation and configuration. These are provided as usage instructions and triggers for the agent, rather than being automatically executed or used for malicious purposes.\n- [DATA_EXFILTRATION]: No data exfiltration patterns were identified. While the skill's purpose involves identifying sensitive data like credentials or PII, it does not include instructions to transmit this data to unauthorized external endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
May 23, 2026, 02:37 PM
Security Audit — agent-trust-hub — awesome-claude-code-security-compliance-suite