dotnet-mvc

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and provides guidance on ASP.NET Core MVC development best practices. It does not contain any executable code, scripts, or commands.
  • [DATA_EXPOSURE]: No hardcoded credentials or sensitive file paths were detected. The skill actually encourages the separation of database entities from views (ViewModels), which is a data protection best practice.
  • [REMOTE_CODE_EXECUTION]: There are no external downloads or remote script execution patterns. All references point to official Microsoft documentation.
  • [PROMPT_INJECTION]: The instructions do not contain any attempts to override safety filters or bypass system guidelines. The language is professional and focused on development expertise.
  • [COMMAND_EXECUTION]: The skill does not perform any shell command execution or system-level operations. It relies on the user having the .NET SDK installed locally for their own development environment.
  • [INDIRECT_PROMPT_INJECTION]: While the skill assists in generating code based on user requests, it does not ingest or process untrusted external data in a way that could lead to injection. It includes explicit instructions to implement security features like Antiforgery tokens and Razor escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 04:46 AM
Security Audit — agent-trust-hub — dotnet-mvc