infosec-engineer
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality, industry-standard security documentation including STRIDE threat modeling, OWASP Top 10 remediation guidance, and templates for security policies (e.g., Access Control, Incident Response).
- [EXTERNAL_DOWNLOADS]: Includes instructions for the user to install official Model Context Protocol (MCP) servers from trusted organizations such as Microsoft, GitHub, and Atlassian, as well as community-provided servers from the public MCP registry for task automation.
- [COMMAND_EXECUTION]: Recommends the use of standard security CLI tools like 'trivy', 'npm audit', 'pip-audit', and 'bandit' for conducting vulnerability assessments and code reviews.
- [DATA_EXPOSURE_AND_EXFILTRATION]: Provides correct security practices for managing sensitive information, such as advising against hardcoded secrets and recommending the use of environment variables or dedicated secrets managers.
- [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface as it is designed to analyze code files, pull request diffs, and security findings from external platforms.
- Ingestion points: Git repository content, PR descriptions, and issue tracking data via MCP integrations (identified in
references/integrations.md). - Boundary markers: The skill does not currently implement explicit delimiters or instructions to ignore embedded commands in processed data.
- Capability inventory: Capable of reading project files, performing security scans, and managing issues or pull requests when configured by the user.
- Sanitization: No specific sanitization or filtering logic is defined for the external data being processed.
Audit Metadata