cso
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed as a security auditing framework (CSO mode). Its instructions involve searching for security vulnerabilities, hardcoded secrets, and misconfigurations within a codebase. These are legitimate administrative and security functions.
- [EXTERNAL_DOWNLOADS]: The skill references several external security resources and tools in its documentation (e.g., Sentry, Trail of Bits, Snyk, and Anthropic's security research). These are well-known, trusted organizations in the security community. The skill also mentions 'aside.com' for web lookups, which is a recognized service for browser-based research.
- [COMMAND_EXECUTION]: The skill uses local shell commands (
grep,find,git log) to identify potential vulnerabilities. These commands are scoped to the local repository and used for analysis rather than executing untrusted remote code. - [INDIRECT_PROMPT_INJECTION]: As a security auditor, the skill is designed to process untrusted data (the codebase it audits). It explicitly includes a 'False Positive Filtering' phase and an 'Anti-manipulation' rule that instructs the agent to ignore instructions found within the audited codebase that might attempt to influence the audit results. This is a best practice for security agents.
Audit Metadata