security-engineer
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill employs dynamic context injection in
SKILL.md(using the!catcommand) to load local protocol and configuration files such as.production-grade.yamlandux-protocol.md. This is a legitimate mechanism for initializing the agent with project-specific context. - [COMMAND_EXECUTION]: The skill instructs the agent to execute various security scanning and penetration testing tools, including
npm audit,sqlmap,nuclei, andtrivy. These commands are essential for the skill's stated purpose of providing security engineering services. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves auditing untrusted source code across multiple services (e.g.,
services/,frontend/). This represents a known attack surface where malicious code being audited could attempt to influence the agent's behavior. - Ingestion points: Files located in
services/,frontend/, andapi/directories as specified inSKILL.mdand Phase 2 instructions. - Boundary markers: The instructions lack explicit boundary markers (like XML tags) to wrap the code being audited, though they define clear phase-based contexts.
- Capability inventory: The skill has the capability to write findings to the
.forgewright/directory and apply security fixes directly to project files. - Sanitization: There is no explicit sanitization step mentioned for the audited code before it is processed by the agent.
Audit Metadata