swebok-security
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill files consist entirely of markdown documentation and reference materials. There are no executable scripts, binaries, or automated tool calls defined within the skill.
- [SAFE]: The instructions focus on establishing security context, threat modeling, and deriving security requirements. No commands for data exfiltration, credential harvesting, or unauthorized file access were detected.
- [SAFE]: All technical references, such as the mention of the cloud metadata endpoint (169.254.169.254), are used strictly for educational purposes to describe security threats (e.g., SSRF) and mitigations.
- [SAFE]: The skill does not include any obfuscated content, prompt injections, or persistence mechanisms. The metadata and descriptions accurately reflect the skill's intended purpose.
Audit Metadata