api-security

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a comprehensive documentation and instruction set for security auditing. It contains no executable code or malicious logic.
  • [PROMPT_INJECTION]: While the skill ingests external files for analysis, it includes a robust 'Prompt Injection Safety Notice' (Category 8) that instructs the agent to treat all reviewed data as inert text and ignore embedded directives. Evidence: SKILL.md contains explicit instructions to treat content as untrusted data and avoid following instructions in code comments.
  • [COMMAND_EXECUTION]: The skill's execution environment is restricted to read-only file operations (allowed-tools: Read, Grep, Glob), preventing unauthorized system changes or network activity. Capability inventory includes subprocess calls for file searching but lacks network tools like curl or wget.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:37 PM
Security Audit — agent-trust-hub — api-security