secure-ai-agent-coding

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a security framework and educational resource for AI agent development. No indicators of prompt injection, data exfiltration, or malicious execution were found.
  • [COMMAND_EXECUTION]: The scripts/test_skill.py script uses subprocess.run to execute internal validation tools (validate.py and scan_patterns.py). These operations are benign and intended for internal consistency checks.
  • [PROMPT_INJECTION]: Instructional text in references/threat-model.md describes prompt injection as a threat scenario. This usage is educational and does not constitute an attempt to manipulate the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 11:06 AM