secure-coding

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a pure security-hardening toolset designed to assist developers in writing secure code. It correctly identifies its own scope as defending application code while deferring agent-specific security or infrastructure networking to other specialized skills.
  • [COMMAND_EXECUTION]: The provided scripts/verify.sh executes several standard security scanning tools (gitleaks, semgrep, pip-audit, osv-scanner, npm audit, govulncheck). These are executed locally on the user's repository and are used for identification of secrets, SAST findings, and vulnerable dependencies. The script is idempotent, read-only, and performs legitimate security auditing tasks.
  • [EXTERNAL_DOWNLOADS]: The skill references standard package registries (NPM, PyPI, Go) and security tool repositories (GitHub). The verify.sh script may download security rules for Semgrep if SECURE_CODING_SEMGREP_AUTO=1 is explicitly set by the user; otherwise, it operates on local configurations. These are standard practices for security tools.
  • [PROMPT_INJECTION]: The skill includes instructions to ignore embedded instructions in untrusted data (Indirect Prompt Injection defense) and explicitly states that it is not intended for agent-safety guardrails, which are handled by a different skill. No malicious prompt injection patterns were found.
  • [DATA_EXFILTRATION]: No patterns of data exfiltration were detected. The skill focuses on preventing exfiltration in the user's application (e.g., SSRF defense, IDOR prevention) rather than performing any network operations itself.
  • [CREDENTIALS_UNSAFE]: The skill provides best practices for secret management (using env vars, secret managers, and .gitignore) and provides a runbook for rotating and scrubbing exposed secrets. It does not contain or solicit hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:56 AM
Security Audit — agent-trust-hub — secure-coding