security-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided project code to identify vulnerabilities. It has the capability to write security reports and suggest or apply code changes. This ingestion of external data represents a potential surface for indirect prompt injection; however, this is a necessary function of a security analysis tool, and the skill provides guidance on minimizing functional regressions during fixes.
- [SAFE]: The skill instructions and reference materials are transparently written and promote secure development practices. There is no evidence of command injection, credential harvesting, or unauthorized network operations. External references point to well-known technology organizations and official documentation.
Audit Metadata