security-sast-dast
Warn
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [METADATA_POISONING]: Eight reference files (including 'architecture-patterns.md', 'code-organization.md', and 'testing-strategies.md') contain deceptive labeling. While claiming to be 'Ultimate Deep Dives' for Staff Engineers, they consist of approximately 1,200 sections of repetitive filler text and code snippets across multiple files.
- [INDIRECT_PROMPT_INJECTION]: The inclusion of massive amounts of repetitive technical filler (estimated at over 200,000 words) constitutes a 'context bomb' or resource exhaustion vector (8f). This can be used to bypass security filtering or cause the agent to lose focus on its safety constraints by saturating its context window.
- [COMMAND_EXECUTION]: The skill instructs the agent to configure and execute complex command-line tools such as 'semgrep', 'zaproxy' (ZAP), and 'sonar-scanner'. This involves significant interaction with the shell environment.
- [EXTERNAL_DOWNLOADS]: The skill encourages the installation and use of various third-party security tools and GitHub Actions. While the tools mentioned (Semgrep, ZAP, Snyk, CodeQL) are reputable industry standards, they represent an external dependency surface.
Audit Metadata