sota-c-cpp
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides detailed technical documentation and audit checklists for software engineering tasks. All included shell commands are for legitimate diagnostic and auditing purposes using standard tools like grep, clang-tidy, and CMake.
- [EXTERNAL_DOWNLOADS]: The skill references established software engineering documentation and compiler hardening guides from trusted organizations and well-known services, including the Open Source Security Foundation (OpenSSF), ISO C++ Committee, and SEI CERT.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a framework for auditing untrusted source code, which constitutes a potential ingestion point for indirect instructions. However, the skill incorporates mitigation strategies by requiring findings to be backed by technical evidence from automated sanitizers and static analysis tools, rather than relying solely on the content of the data being processed.
Audit Metadata