agency-senior-secops-engineer

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a defensive security role and provides clear guidelines for identifying and remediating common software vulnerabilities.
  • [SAFE]: It includes numerous examples of insecure code (e.g., hardcoded credentials, SQL injection patterns) strictly for the purpose of defining detection logic.
  • [SAFE]: The skill promotes secure engineering practices, such as centralized secret management, strict input validation, and defensive logging strategies.
  • [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted code from users for auditing purposes. While this creates a potential surface for indirect prompt injection, it is central to the skill's primary function. The risk is managed through structured reporting requirements and a security-first instruction set.
  • Ingestion points: SKILL.md (Automatic Security Scan instructions)
  • Boundary markers: SKILL.md (Structured scan output block defined in instructions)
  • Capability inventory: SKILL.md (Code review, vulnerability assessment, remediation guidance)
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:58 PM
Security Audit — agent-trust-hub — agency-senior-secops-engineer