security-expert

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The documentation includes code snippets showing both vulnerable and secure methods for executing shell commands in Node.js. In references/OWASP_TOP_10_VULNERABILITIES.md, it illustrates a command injection attack payload using rm -rf / to educate users on why direct execution of user input is dangerous. The skill's allowed tools are restricted to specific security utilities (nmap, burpsuite, zap).
  • [INDIRECT_PROMPT_INJECTION]: As a security expert tool, the skill is designed to analyze and provide advice on user-provided code or security scenarios. It provides robust sanitization examples (e.g., escapeHtml for XSS prevention, path.basename for path traversal prevention, and express-validator for input filtering) to guide the agent in handling untrusted data securely.
  • [SAFE]: The skill implements security best practices, such as using environment variables for secrets (process.env.ENCRYPTION_KEY), employing cryptographically secure random number generators (crypto.randomBytes), and recommending established libraries over custom implementations. All external references point to reputable security organizations (OWASP, NIST, CWE).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:42 PM
Security Audit — agent-trust-hub — security-expert