skills/descope/skills/auth-review/Gen Agent Trust Hub

auth-review

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a collection of markdown-based instructions for manual security review tasks. It contains no executable code, script components, or network operations. The instructions follow security best practices, such as requiring evidence for findings and redacting sensitive data like secrets or tokens from reports.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface as it processes untrusted source code during its audit phases. This is inherent to the skill's primary purpose of code analysis. 1. Ingestion points: Reads all repository files including source code, manifests, and configuration files. 2. Boundary markers: Not explicitly defined for the audited content. 3. Capability inventory: Operations are limited to reading local files and writing a report to the local file system. 4. Sanitization: No specific sanitization or escaping of the audited code is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:30 PM
Security Audit — agent-trust-hub — auth-review