security-audit
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a sophisticated security auditing methodology. While it involves complex instructions for 'breaking' codebases, this is the explicit primary purpose of the skill (a security audit tool).
- [SAFE]: The
SKILL.mdfile references an official Cloudflare GitHub repository in its metadata (author: https://github.com/cloudflare/security-audit-skill). Cloudflare is a well-known and trusted technology service. - [SAFE]: The skill uses several JSON and CJS files (
report-schema.json,validate-findings.cjs) to enforce structural integrity and factual verification of the audit results. These are local configuration files and do not perform remote code execution or exfiltration. - [SAFE]: There are no signs of prompt injection, obfuscation, persistence mechanisms, or credential theft. The use of sub-agents and tool-calling is standard for advanced agentic workflows.
Audit Metadata