secure-code-guardian
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No instructions attempting to override agent behavior or bypass safety guidelines were found. The skill maintains a consistent focus on security hardening.
- [DATA_EXFILTRATION]: No suspicious network operations or hardcoded credentials were detected. Code examples correctly demonstrate the use of environment variables for secrets rather than hardcoding them.
- [REMOTE_CODE_EXECUTION]: No patterns involving untrusted remote code execution or suspicious package downloads were found. Code snippets recommend well-known, established libraries for security tasks.
- [OBFUSCATION]: No encoded content, zero-width characters, or homoglyph attacks were detected in the instructions or the provided reference files.
- [INDIRECT_PROMPT_INJECTION]: The skill provides guidance for processing user input and external data. It correctly identifies this as a potential attack surface and provides extensive sanitization and validation patterns (using tools like Zod and DOMPurify) to mitigate these risks.
Audit Metadata