security-engineer

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs dynamic context injection in SKILL.md (using the !cat command) to load local protocol and configuration files such as .production-grade.yaml and ux-protocol.md. This is a legitimate mechanism for initializing the agent with project-specific context.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various security scanning and penetration testing tools, including npm audit, sqlmap, nuclei, and trivy. These commands are essential for the skill's stated purpose of providing security engineering services.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves auditing untrusted source code across multiple services (e.g., services/, frontend/). This represents a known attack surface where malicious code being audited could attempt to influence the agent's behavior.
  • Ingestion points: Files located in services/, frontend/, and api/ directories as specified in SKILL.md and Phase 2 instructions.
  • Boundary markers: The instructions lack explicit boundary markers (like XML tags) to wrap the code being audited, though they define clear phase-based contexts.
  • Capability inventory: The skill has the capability to write findings to the .forgewright/ directory and apply security fixes directly to project files.
  • Sanitization: There is no explicit sanitization step mentioned for the audited code before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 08:02 AM
Security Audit — agent-trust-hub — security-engineer