api-security
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a comprehensive documentation and instruction set for security auditing. It contains no executable code or malicious logic.
- [PROMPT_INJECTION]: While the skill ingests external files for analysis, it includes a robust 'Prompt Injection Safety Notice' (Category 8) that instructs the agent to treat all reviewed data as inert text and ignore embedded directives. Evidence: SKILL.md contains explicit instructions to treat content as untrusted data and avoid following instructions in code comments.
- [COMMAND_EXECUTION]: The skill's execution environment is restricted to read-only file operations (allowed-tools: Read, Grep, Glob), preventing unauthorized system changes or network activity. Capability inventory includes subprocess calls for file searching but lacks network tools like curl or wget.
Audit Metadata