secure-coding
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a pure security-hardening toolset designed to assist developers in writing secure code. It correctly identifies its own scope as defending application code while deferring agent-specific security or infrastructure networking to other specialized skills.
- [COMMAND_EXECUTION]: The provided
scripts/verify.shexecutes several standard security scanning tools (gitleaks,semgrep,pip-audit,osv-scanner,npm audit,govulncheck). These are executed locally on the user's repository and are used for identification of secrets, SAST findings, and vulnerable dependencies. The script is idempotent, read-only, and performs legitimate security auditing tasks. - [EXTERNAL_DOWNLOADS]: The skill references standard package registries (NPM, PyPI, Go) and security tool repositories (GitHub). The
verify.shscript may download security rules for Semgrep ifSECURE_CODING_SEMGREP_AUTO=1is explicitly set by the user; otherwise, it operates on local configurations. These are standard practices for security tools. - [PROMPT_INJECTION]: The skill includes instructions to ignore embedded instructions in untrusted data (Indirect Prompt Injection defense) and explicitly states that it is not intended for agent-safety guardrails, which are handled by a different skill. No malicious prompt injection patterns were found.
- [DATA_EXFILTRATION]: No patterns of data exfiltration were detected. The skill focuses on preventing exfiltration in the user's application (e.g., SSRF defense, IDOR prevention) rather than performing any network operations itself.
- [CREDENTIALS_UNSAFE]: The skill provides best practices for secret management (using env vars, secret managers, and
.gitignore) and provides a runbook for rotating and scrubbing exposed secrets. It does not contain or solicit hardcoded credentials.
Audit Metadata