sota

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust security methodology for AI agents. It explicitly mandates verifying claims against code or official documentation, avoiding reliance on training data for sensitive information like CVEs or tool capabilities.
  • [SAFE]: The routing logic and operating principles prioritize security-relevant decisions by requiring a 'stop-and-ask' approach before proceeding with critical changes to authentication, cryptography, or secrets handling.
  • [SAFE]: The audit methodology (rules/01-audit-methodology.md) defines a high-quality evidence standard, requiring specific file/line references, standard mapping (CWE, OWASP), and concrete remediation steps for every finding.
  • [SAFE]: Security hygiene is emphasized through principles like redacting secrets from reports, maintaining a read-only-by-default posture during audits, and ensuring reproducibility by pinning targets to specific commit hashes.
  • [SAFE]: No obfuscation, prompt injection, or unauthorized data exfiltration patterns were found. The tool matrix references standard, well-known security utilities used for professional auditing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:06 PM
Security Audit — agent-trust-hub — sota