securite-developpement

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_ACCESS]: The skill is designed to perform security audits by reading the project's source code, configuration files, and CI/CD pipelines. This data access is essential for its primary purpose of identifying security vulnerabilities.
  • [FILE_SYSTEM_OPERATIONS]: The skill automatically creates an audits/ directory and writes audit reports in Markdown and JSON formats. These operations are limited to the project root and are explicitly documented as part of the tool's reporting functionality.
  • [INDIRECT_PROMPT_INJECTION]: As an auditing tool that processes untrusted external code, there is a theoretical surface for indirect prompt injection. However, the skill includes a specific 'Validation' step in its workflow to verify findings against the actual code, which serves as a manual check against potential manipulation.
  • [EXTERNAL_REFERENCES]: All external links in the skill point to official French government domains (cyber.gouv.fr), providing users with legitimate cybersecurity guidelines and recommendations.
  • [NO_CODE_EXECUTION]: The skill consists entirely of instructional prompts and configuration schemas. It does not contain or execute any scripts, binaries, or remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 11:28 AM
Security Audit — agent-trust-hub — securite-developpement