security-audit

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute specific shell commands for dependency auditing based on the detected project ecosystem. These tools include npm audit, pnpm audit, yarn npm audit, pip-audit, cargo audit, govulncheck, bundle audit, composer audit, and mix audit. These are standard, industry-recognized security tools used for their intended purpose within the skill's security-audit context.
  • [EXTERNAL_DOWNLOADS]: The mentioned dependency auditing tools typically perform network requests to official package registries or vulnerability databases (such as the GitHub Advisory Database or PyPI) to check for known security vulnerabilities. These are well-known services necessary for the audit function.
  • [SAFE]: The skill follows security best practices by focusing on high-confidence, exploitable findings and providing clear guidelines to avoid reporting common false positives or theoretical issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 02:41 PM
Security Audit — agent-trust-hub — security-audit