securite-developpement
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [DATA_ACCESS]: The skill is designed to perform security audits by reading the project's source code, configuration files, and CI/CD pipelines. This data access is essential for its primary purpose of identifying security vulnerabilities.
- [FILE_SYSTEM_OPERATIONS]: The skill automatically creates an
audits/directory and writes audit reports in Markdown and JSON formats. These operations are limited to the project root and are explicitly documented as part of the tool's reporting functionality. - [INDIRECT_PROMPT_INJECTION]: As an auditing tool that processes untrusted external code, there is a theoretical surface for indirect prompt injection. However, the skill includes a specific 'Validation' step in its workflow to verify findings against the actual code, which serves as a manual check against potential manipulation.
- [EXTERNAL_REFERENCES]: All external links in the skill point to official French government domains (cyber.gouv.fr), providing users with legitimate cybersecurity guidelines and recommendations.
- [NO_CODE_EXECUTION]: The skill consists entirely of instructional prompts and configuration schemas. It does not contain or execute any scripts, binaries, or remote code.
Audit Metadata