security-audit

Fail

Audited by Gen Agent Trust Hub on May 17, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE]: The skill's primary function is to guide an AI agent through a multi-phase security audit process, including threat modeling, source-to-sink dataflow mapping, and systematic vulnerability analysis. The logic is consistent with its stated goal.
  • [SAFE]: Automated AV alerts in references/source-sink-mapping.md and YARA alerts in references/language-footguns/python.md are false positives. These files contain checklists of security vulnerabilities (e.g., HTTP sources, eval sinks) which the auditor should look for in target code. The presence of these terms triggered generic heuristic detectors.
  • [SAFE]: The skill implements a robust security mindset for the agent, explicitly instructing it to 'assume any untrusted input is hostile' and to 'verify validation, encoding, authorization, and trust assumptions' at every step. This directly mitigates the risk of indirect prompt injection from the codebase being audited.
  • [SAFE]: No obfuscated content, hardcoded credentials, or unauthorized network operations were detected. All described workflows (reading documentation, scanning git history, and analyzing source code) are standard and necessary for a code auditing tool.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
May 17, 2026, 02:09 PM
Security Audit — agent-trust-hub — security-audit