dast-config

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for security engineers to audit application security tool configurations. It uses standard file search tools (Glob, Grep) and read operations to identify and analyze DAST setup files.
  • [PROMPT_INJECTION]: No malicious prompt injection patterns were found. The skill proactively includes an 'Indirect Prompt Injection Safety Notice' instructing the agent to treat target configurations as untrusted data.
  • [EXTERNAL_DOWNLOADS]: The skill references official security resources and GitHub Actions from the OWASP ZAP project (zaproxy/action-baseline, zaproxy/action-full-scan). These are well-known security tools and are treated as safe references.
  • [DATA_EXFILTRATION]: While the skill searches for configuration files (which may contain sensitive environment variable references), it does not request network access or any tools capable of transmitting data externally.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, unverified dependencies, or dynamic execution of untrusted scripts were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — dast-config