secure-code-review

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a documentation-based framework for conducting security audits. It contains no executable logic, hidden instructions, or exfiltration mechanisms.
  • [REMOTE_CODE_EXECUTION]: The file contains snippets of potentially dangerous code (e.g., eval(), pickle.loads(), JSON.parse(), and Class.forName()). These are provided strictly as educational examples of what to look for during a security review and are not intended for execution by the agent or host.
  • [COMMAND_EXECUTION]: The skill lists several security scanning tools (e.g., bandit, semgrep, eslint) and their usage commands. These are recommendations for manual use by the security reviewer and do not represent automated execution by the skill itself.
  • [PROMPT_INJECTION]: The skill includes instructions on how to perform a security assessment but does not contain any patterns designed to bypass AI safety guardrails or override system prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 12:25 AM
Security Audit — agent-trust-hub — secure-code-review