draft-security-advisory

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions for formatting vulnerability reports into GitHub Security Advisories. It does not include scripts, tools, or commands. No instances of obfuscation, hardcoded credentials, or unauthorized network activity were found. The skill emphasizes data minimization by instructing the agent to remove specific details like file paths or code snippets, which is a security best practice for advisory writing. While it processes untrusted user input (vulnerability reports), the lack of executable capabilities and the requirement for a rigid, generalized output format mitigate potential indirect prompt injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:33 AM
Security Audit — agent-trust-hub — draft-security-advisory