codeql-semgrep
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFENO_CODEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill serves as a guide for the AI agent to understand and implement static analysis using industry-standard tools. No malicious patterns such as prompt injection, data exfiltration, or obfuscation were detected.
- [NO_CODE]: The skill consists primarily of markdown documentation, Mermaid diagrams, and configuration templates (YAML, QL). It does not include executable scripts or binaries that could be used for malicious purposes.
- [EXTERNAL_DOWNLOADS]: The documentation references official and well-known GitHub Actions from Semgrep and GitHub for CI/CD integration. These are standard, trusted resources in the software development lifecycle.
Audit Metadata