owasp-top-10-web

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a purpose-built security tool for performing web application vulnerability assessments based on the industry-standard OWASP Top 10:2021 framework.
  • [SAFE]: The instructions include a dedicated 'Prompt Injection Safety Notice' that explicitly directs the agent to treat target source code as untrusted data, disregard any instructions embedded within target files, and maintain output integrity. This effectively mitigates the risk of indirect prompt injection.
  • [SAFE]: Tool access is restricted to passive analysis capabilities (Read, Grep, Glob), which aligns with the principle of least privilege for a static code auditing tool.
  • [SAFE]: All external references (OWASP, NIST, MITRE) are to official and well-known documentation sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — owasp-top-10-web