application-security-requirements

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, exfiltration code, or hardcoded credentials were found in the skill files. The guidelines are strictly defensive.
  • [NO_CODE]: The skill consists only of Markdown files and does not include any scripts or binaries.
  • [PROMPT_INJECTION]: The skill's role in auditing code diffs and CMS-authored content creates an indirect prompt injection surface. 1. Ingestion points: Code snippets and git diffs provided for analysis. 2. Boundary markers: No specific delimiters are mandated in the instructions to isolate untrusted inputs. 3. Capability inventory: The auditing agent typically possesses read access to the local codebase. 4. Sanitization: The skill does not define methods for sanitizing or escaping the content being audited.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 07:27 AM
Security Audit — agent-trust-hub — application-security-requirements