attack-path-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- Security Analysis Workflow: The skill implements a structured methodology for tracing security findings from source to sink. It emphasizes using repository evidence to build factual attack paths, which is a standard security practice for identifying vulnerabilities.
- Network Connectivity for Verification: The instructions allow for the use of network connectivity to confirm deployment context and reachable surfaces. This capability is used to help distinguish between theoretical bugs and realistically exploitable security issues.
- Artifact and Policy Management: The skill interacts with defined artifact paths and policy documents to maintain consistency in reporting. This approach ensures that findings are documented and prioritized according to a centralized threat model.
- Severity Calibration Guidance: The skill includes comprehensive criteria for adjusting the severity of findings based on impact and likelihood. This helps ensure that reportable issues are correctly identified and that lower-risk bugs are categorized according to project policy.
Audit Metadata