security-threat-modeling
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of documentation, process guidelines, and templates for security engineering. It promotes industry-standard practices including the OWASP ASVS, NIST SSDF, and CISA Secure by Design principles. The instructions prioritize backend enforcement over frontend validation and emphasize the importance of audit logs, tenant isolation, and secret management.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze external project data such as code changes, data flows, and API contracts. While these ingestion points represent an attack surface for indirect prompt injection, the skill includes explicit process steps (e.g., checking negative paths, abuse cases, and trust boundaries) that encourage adversarial reasoning by the agent, effectively mitigating the risk of being misled by malicious content within the analyzed assets. The skill provides clear templates for 'Security notes' and 'Security review' which act as structural boundaries for processing data.
Audit Metadata