security-best-practices
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily instructional and reference-based, providing the agent with guidelines on how to identify and report security vulnerabilities using standard industry practices.
- [DATA_EXFILTRATION]: Every reference document (e.g., for Django, Express, FastAPI, Go) contains a strict rule prohibiting the agent from requesting, logging, or committing secrets such as API keys, passwords, or session tokens.
- [PROMPT_INJECTION]: The instructions include a section on 'Overrides' allowing the agent to follow project-specific rules that might bypass general best practices. While this presents a surface for indirect prompt injection via codebase comments, the agent's capabilities are limited to generating markdown reports and suggesting code changes, with no access to dangerous tools like shell execution or network exfiltration.
- [EXTERNAL_DOWNLOADS]: The reference files include links to trusted external sources such as MDN Web Docs, OWASP Cheat Sheets, and official framework documentation (Next.js, Django, Go, etc.). These references are documented neutrally and used for informational purposes only.
Audit Metadata