security-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation includes code snippets showing both vulnerable and secure methods for executing shell commands in Node.js. In
references/OWASP_TOP_10_VULNERABILITIES.md, it illustrates a command injection attack payload usingrm -rf /to educate users on why direct execution of user input is dangerous. The skill's allowed tools are restricted to specific security utilities (nmap,burpsuite,zap). - [INDIRECT_PROMPT_INJECTION]: As a security expert tool, the skill is designed to analyze and provide advice on user-provided code or security scenarios. It provides robust sanitization examples (e.g.,
escapeHtmlfor XSS prevention,path.basenamefor path traversal prevention, andexpress-validatorfor input filtering) to guide the agent in handling untrusted data securely. - [SAFE]: The skill implements security best practices, such as using environment variables for secrets (
process.env.ENCRYPTION_KEY), employing cryptographically secure random number generators (crypto.randomBytes), and recommending established libraries over custom implementations. All external references point to reputable security organizations (OWASP, NIST, CWE).
Audit Metadata