security-threat-model

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as an instructional framework for security analysis, providing detailed prompts and templates to assist an AI agent in generating threat models for local codebases.\n- [SAFE]: Includes explicit instructions for security hygiene, specifically directing the agent to redact any secrets, keys, or tokens encountered during the analysis process.\n- [NO_CODE]: The skill consists entirely of Markdown instructions and YAML configuration files; it contains no executable scripts, binaries, or automated network operations.\n- [PROMPT_INJECTION]: The skill analyzes untrusted repository data, which is a potential surface for indirect prompt injection. However, it mitigates this by using a structured system persona and explicit instructions to ground all findings in code evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 02:45 AM
Security Audit — agent-trust-hub — security-threat-model