secure-code-guardian

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No instructions attempting to override agent behavior or bypass safety guidelines were found. The skill maintains a consistent focus on security hardening.
  • [DATA_EXFILTRATION]: No suspicious network operations or hardcoded credentials were detected. Code examples correctly demonstrate the use of environment variables for secrets rather than hardcoding them.
  • [REMOTE_CODE_EXECUTION]: No patterns involving untrusted remote code execution or suspicious package downloads were found. Code snippets recommend well-known, established libraries for security tasks.
  • [OBFUSCATION]: No encoded content, zero-width characters, or homoglyph attacks were detected in the instructions or the provided reference files.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides guidance for processing user input and external data. It correctly identifies this as a potential attack surface and provides extensive sanitization and validation patterns (using tools like Zod and DOMPurify) to mitigate these risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 09:03 AM
Security Audit — agent-trust-hub — secure-code-guardian