backend-security-audit
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are purely defensive, focusing on identifying and reporting security weaknesses in the user's own authorized codebase. It explicitly prohibits the generation of exploit payloads or attack instructions.
- [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and analyzing untrusted source code and configuration files from a repository. This creates a surface where malicious instructions hidden in the codebase (e.g., in comments or documentation) could theoretically influence agent behavior. However, the instructions prioritize evidence-based reporting and require user confirmation before any remediation steps, mitigating potential impact.
Audit Metadata