secure-software-engineering

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists exclusively of Markdown documentation and templates. There are no executable scripts (Python, JavaScript, Shell), binaries, or automation files that could lead to command execution or system modification.
  • [SAFE]: All external URLs and resources listed in the documentation belong to trusted and well-known technology and security organizations, including NIST, OWASP, MITRE, and CISA. These are used strictly for reference and do not involve downloading or executing remote code.
  • [SAFE]: The skill includes strong defensive instructions for the agent, explicitly mandating that it treat all user inputs, retrieved content, and external data as untrusted and requiring validation at trust boundaries.
  • [SAFE]: No obfuscation, hidden content, or data exfiltration patterns were identified. The skill's stated purpose (security prevention and guidance) aligns perfectly with its actual content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 03:02 AM
Security Audit — agent-trust-hub — secure-software-engineering