sast-config

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a minimal and restricted set of allowed tools (Read, Grep, Glob) intended for static analysis of configuration files. It does not perform network operations, file writes, or arbitrary command execution.
  • [SAFE]: The skill includes a proactive 'Prompt Injection Safety Notice' designed to mitigate indirect prompt injection. This section explicitly instructs the agent to treat all ingested configuration data (e.g., rule messages or descriptions) as untrusted and to ignore any potential instructions embedded within them.
  • [SAFE]: Analysis of external references confirms that all URLs and resources point to official, trusted security organizations (OWASP, MITRE/CWE) and well-known tool providers (GitHub, Semgrep).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:37 PM
Security Audit — agent-trust-hub — sast-config