responsible-security-disclosure
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill establishes strict confidentiality protocols, explicitly prohibiting the public disclosure of vulnerabilities or proof-of-concept code.
- [SAFE]: Includes comprehensive data minimization instructions, mandating the redaction of credentials, tokens, and PII before any report generation or sharing.
- [SAFE]: Recognizes the risk of untrusted data in security contexts, specifically instructing the agent to inspect submitted PoCs and execute them only in isolated environments when necessary.
- [SAFE]: Mandates human approval for all external actions, ensuring that no reports are submitted or published without explicit user review of the content and recipient.
- [SAFE]: References authoritative security resources and policies from trusted organizations like the OpenSSF, NIST, and GitHub to guide the discovery of safe reporting channels.
Audit Metadata