skills/garrytan/gstack/cso/Gen Agent Trust Hub

cso

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a security auditing framework (CSO mode). Its instructions involve searching for security vulnerabilities, hardcoded secrets, and misconfigurations within a codebase. These are legitimate administrative and security functions.
  • [EXTERNAL_DOWNLOADS]: The skill references several external security resources and tools in its documentation (e.g., Sentry, Trail of Bits, Snyk, and Anthropic's security research). These are well-known, trusted organizations in the security community. The skill also mentions 'aside.com' for web lookups, which is a recognized service for browser-based research.
  • [COMMAND_EXECUTION]: The skill uses local shell commands (grep, find, git log) to identify potential vulnerabilities. These commands are scoped to the local repository and used for analysis rather than executing untrusted remote code.
  • [INDIRECT_PROMPT_INJECTION]: As a security auditor, the skill is designed to process untrusted data (the codebase it audits). It explicitly includes a 'False Positive Filtering' phase and an 'Anti-manipulation' rule that instructs the agent to ignore instructions found within the audited codebase that might attempt to influence the audit results. This is a best practice for security agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:04 PM
Security Audit — agent-trust-hub — cso