security-audit

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a sophisticated security auditing methodology. While it involves complex instructions for 'breaking' codebases, this is the explicit primary purpose of the skill (a security audit tool).
  • [SAFE]: The SKILL.md file references an official Cloudflare GitHub repository in its metadata (author: https://github.com/cloudflare/security-audit-skill). Cloudflare is a well-known and trusted technology service.
  • [SAFE]: The skill uses several JSON and CJS files (report-schema.json, validate-findings.cjs) to enforce structural integrity and factual verification of the audit results. These are local configuration files and do not perform remote code execution or exfiltration.
  • [SAFE]: There are no signs of prompt injection, obfuscation, persistence mechanisms, or credential theft. The use of sub-agents and tool-calling is standard for advanced agentic workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:13 PM
Security Audit — agent-trust-hub — security-audit