security-review
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a template for performing security reviews. It provides guidelines for identifying vulnerabilities like prompt injection, hardcoded secrets, and insecure configurations.
- [COMMAND_EXECUTION]: The skill mentions using
npx ai-devkit@latestfor storing and searching findings. This is standard use of a tool within the specified ecosystem and does not pose a risk. - [PROMPT_INJECTION]: While the skill contains instructions on how to detect prompt injection, it does not contain any malicious override patterns or bypasses itself. It explicitly warns developers to treat all external content as untrusted data.
- [DATA_EXPOSURE]: The skill includes instructions to identify sensitive data exposure in target codebases but correctly mandates that secrets found during review should not be surfaced or logged.
Audit Metadata