path-traversal
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a comprehensive methodology for identifying directory traversal vulnerabilities in JavaScript, Python, and Go. It correctly identifies dangerous sinks and suggests robust validation techniques like path resolution combined with prefix checking.
- [SAFE]: The search commands (grep) are used for static analysis of the codebase, which is consistent with the skill's stated purpose of auditing for security flaws.
- [SAFE]: Proof-of-concept templates in
references/poc-skeleton.mdare provided for documentation and verification of findings. These are static examples and do not involve remote code execution or unauthorized data exfiltration. - [SAFE]: The skill does not attempt to download external scripts, exfiltrate sensitive data, or bypass AI safety guidelines.
Audit Metadata