sast-configuration
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install Semgrep from the official Python package registry and the CodeQL extension from GitHub's official repository.
- [COMMAND_EXECUTION]: Mentions a local automation script
scripts/run-sast.shand provides standard Docker commands for running SonarQube locally. - [PROMPT_INJECTION]: The skill operates on application source code to perform security analysis. This ingestion of external data is the intended primary purpose of the skill and follows standard security testing workflows.
Audit Metadata