tool-allowlist
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional, detailing how to implement security controls like tool allowlisting and policy gateways to prevent unauthorized tool execution. It contains no malicious instructions or executable code.
- [EXTERNAL_DOWNLOADS]: The skill references several external resources, including documentation from AgentPatterns and Vouched.id, as well as security tools from SecAI-Hub and Spin42. These are provided as reference materials for security implementation and do not involve automated code execution or dependency installation.
- [DATA_EXPOSURE]: While the skill mentions sensitive file paths such as
/etc/shadow, it does so exclusively as an example of what should be included in a denylist policy to protect system integrity. No actual attempts to access or exfiltrate sensitive data were found.
Audit Metadata