security-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to perform security audits using standard command-line utilities. It provides examples for running SAST tools (e.g., bandit, semgrep), secret scanners (gitleaks, trufflehog), and network reconnaissance tools (nmap, dig). These operations are consistent with the skill's primary purpose.
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of security tools from well-known package registries (NPM, PyPI, and Homebrew). For example, it provides instructions for npm install eslint-plugin-security, pip install bandit, and brew install gitleaks. These downloads are associated with established security software used in professional auditing workflows.
  • [DATA_EXPOSURE]: While the skill contains patterns for identifying hardcoded secrets and sensitive files (e.g., .env, .aws/credentials), these are used exclusively for auditing local environments as part of its core functionality and are not exfiltrated to external destinations.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized access attempts were detected. The skill includes strong 'Must Not Do' constraints, emphasizing the importance of authorization and the prevention of service disruption during testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — security-reviewer