security-expert

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill provides instructions for acting as a security advisor using recognized methodologies such as STRIDE, PASTA, and OWASP Top 10.\n- [PROMPT_INJECTION]: The skill is designed to analyze external data via tools like WebFetch, which creates an attack surface for indirect prompt injection. Evidence chain:\n
  • Ingestion points: External content is ingested via WebFetch and user-provided designs or code (SKILL.md).\n
  • Boundary markers: Absent; there are no explicit instructions to ignore embedded commands in analyzed content.\n
  • Capability inventory: The skill is restricted to information retrieval and analysis tools; it has no capabilities for subprocess execution, arbitrary file writing, or network exfiltration.\n
  • Sanitization: Absent; the skill relies on the underlying model's inherent safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 10:20 AM
Security Audit — agent-trust-hub — security-expert