security-best-practices

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of markdown documentation and configuration files providing security audit guidelines for various frameworks (Django, FastAPI, Flask, Express, Vue, Go). No executable code, shell scripts, or binary files were found within the skill package.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external code provided in the user's project context. While this untrusted data presents a potential injection surface, the skill's instructions require the agent to generate structured reports with evidence, citations, and line numbers, facilitating human oversight and verification of the agent's findings.
  • [EXTERNAL_DOWNLOADS]: The skill's reference documentation contains numerous links to well-known and trusted external resources for security research, including official GitHub repositories (e.g., github/awesome-copilot), the OWASP Cheat Sheet Series, and official language/framework documentation (MDN, Django Project, Vue.js). These references are purely informational and target established, reputable services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:17 PM
Security Audit — agent-trust-hub — security-best-practices