sota-code-security

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a collection of high-quality security documentation and rules. It contains no scripts, binary files, or network-active components.
  • [PROMPT_INJECTION]: The automated detection of phrases like "ignore previous instructions" in the rules regarding LLM security was determined to be a false positive. These strings are provided as specific examples of attack patterns for developers to recognize and defend against in their applications, not as instructions to the AI agent.
  • [DATA_EXFILTRATION]: No exfiltration risks were identified. The documentation provides examples of how attackers might attempt data exfiltration (e.g., using markdown image tags to send data to an external server) to educate users on effective defensive strategies.
  • [COMMAND_EXECUTION]: The skill identifies and defines dangerous command execution sinks that should be avoided in secure codebases, but it does not perform any shell or command execution itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-code-security