security-audit-methodology
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists exclusively of Markdown documentation providing guidance on threat modeling, vulnerability classification, and architecture review. No executable code, shell commands, or external dependencies were identified.
- [NO_CODE]: The skill contains zero executable files or scripts. All reference materials are static documentation intended to guide the agent's reasoning process during an audit.
- [DATA_EXFILTRATION]: While the reference materials describe common targets for data exfiltration (e.g., secrets in .env files or SSH keys) to help an auditor identify risks in a target system, the skill itself does not contain instructions or tools to access or exfiltrate such data from the environment where the agent is running.
- [PROMPT_INJECTION]: The instructions establish a professional persona for security auditing and define a safety boundary requiring explicit authorization before any testing. It does not contain patterns attempting to override agent safety guidelines or bypass system constraints.
Audit Metadata