sota-code-security

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of documentation (markdown files) and does not include any executable scripts, binaries, or active code components. It functions as a knowledge base for the agent.
  • [PROMPT_INJECTION]: A static detector flagged the phrase "ignore previous instructions" in rules/08-llm-ai-security.md. Detailed analysis confirms this is a false positive; the phrase is used within instructional text describing how prompt injection attacks work and how to mitigate them, not as an attempt to override the agent's behavior.
  • [DATA_EXFILTRATION]: The files mention various exfiltration vectors (e.g., ![](https://evil.com/...)) but only as examples of security risks to be audited in other systems. The skill itself does not access or transmit any sensitive data.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides explicit guidance on how to detect and mitigate indirect prompt injection vulnerabilities in agentic applications. It is a defensive resource and does not introduce an attack surface.
  • [COMMAND_EXECUTION]: While the skill mentions numerous CLI tools and commands (e.g., curl, git, docker, npm), these are listed within security checklists and best practice guidelines. The skill contains no code to execute these commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:37 AM
Security Audit — agent-trust-hub — sota-code-security