secure-code-guardian

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No instructions attempting to override agent behavior or bypass safety guidelines were detected. The skill uses standard instructional language for technical guidance.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, sensitive file paths, or unauthorized network operations were found. The skill explicitly promotes secure practices, such as using environment variables for secrets and avoiding sensitive data exposure in logs.
  • [REMOTE_CODE_EXECUTION]: No remote script execution or unverifiable package installations were detected. The code examples use standard, well-known libraries (e.g., bcrypt, jsonwebtoken, zod) for their intended security purposes.
  • [OBFUSCATION]: No obfuscated content, such as multi-layer Base64, zero-width characters, or homoglyphs, was identified in the instructions or reference files.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides defensive patterns for handling untrusted data, including sanitization with DOMPurify and validation with Zod. It correctly identifies injection surfaces and recommends appropriate boundary markers like parameterized queries.
  • [PRIVILEGE_ESCALATION]: No patterns for acquiring elevated permissions, such as sudo or chmod 777, were found.
  • [PERSISTENCE]: No attempts to maintain access across sessions via shell profiles, cron jobs, or registry keys were detected.
  • [DYNAMIC_EXECUTION]: The skill does not generate or execute code at runtime. It discusses execFile only in the context of preventing command injection vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — secure-code-guardian