reviewing-threat-model
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes an 'Anti-injection' rule that explicitly instructs the agent to treat all reviewed content as untrusted data and to ignore any instructions within that content that attempt to suppress the reporting of security threats.
- [DATA_EXFILTRATION]: No network operations or data exfiltration patterns were detected. The skill operates as a reasoning lens for reviewing documents and code provided in the context.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, subprocess calls, or dynamic code execution methods were found. The skill mentions external security tools (pytm, threagile, Threat Dragon) for manual verification purposes only.
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive environment variable access were found. The skill analyzes configuration files in the user's environment to build a threat model but does not exfiltrate or store them.
- [COMMAND_EXECUTION]: No shell command execution or system-level modifications are present in the skill instructions or examples.
Audit Metadata