secure-software-engineering
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of Markdown documentation and templates. There are no executable scripts (Python, JavaScript, Shell), binaries, or automation files that could lead to command execution or system modification.
- [SAFE]: All external URLs and resources listed in the documentation belong to trusted and well-known technology and security organizations, including NIST, OWASP, MITRE, and CISA. These are used strictly for reference and do not involve downloading or executing remote code.
- [SAFE]: The skill includes strong defensive instructions for the agent, explicitly mandating that it treat all user inputs, retrieved content, and external data as untrusted and requiring validation at trust boundaries.
- [SAFE]: No obfuscation, hidden content, or data exfiltration patterns were identified. The skill's stated purpose (security prevention and guidance) aligns perfectly with its actual content.
Audit Metadata