managing-veracode
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes secure patterns for interacting with the Veracode API. Authentication is handled via an environment variable ($VERACODE_HMAC_HEADER), avoiding hardcoded credentials. All shell scripts within the skill properly quote variables when interpolating them into commands, which prevents command injection vulnerabilities. The API interactions target the official Veracode domain (api.veracode.com), which is a well-known and trusted service for application security testing.
Audit Metadata