security-expert
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill provides instructions for acting as a security advisor using recognized methodologies such as STRIDE, PASTA, and OWASP Top 10.\n- [PROMPT_INJECTION]: The skill is designed to analyze external data via tools like
WebFetch, which creates an attack surface for indirect prompt injection. Evidence chain:\n - Ingestion points: External content is ingested via
WebFetchand user-provided designs or code (SKILL.md).\n - Boundary markers: Absent; there are no explicit instructions to ignore embedded commands in analyzed content.\n
- Capability inventory: The skill is restricted to information retrieval and analysis tools; it has no capabilities for subprocess execution, arbitrary file writing, or network exfiltration.\n
- Sanitization: Absent; the skill relies on the underlying model's inherent safety filters.
Audit Metadata