skills/rifteo/skills/finding-writer/Gen Agent Trust Hub

finding-writer

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (scripts/cvss-scorer.py and scripts/cwe-search.py) for data processing. These scripts are self-contained, do not perform network operations, and do not access sensitive file paths. The use of $keyword in the CWE search is limited to searching a local markdown reference file.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill uses locally provided scripts for its functionality.
  • [DATA_EXFILTRATION]: No data exfiltration vectors were identified. The skill does not perform network requests and focuses on formatting user-provided input into a report structure.
  • [PROMPT_INJECTION]: The instructions contain standard guidance for agent behavior (e.g., 'Do NOT apply the finding format') which are legitimate scoping constraints for the tool's purpose. No malicious injection patterns or safety bypasses were found.
  • [SAFE]: All external references (OWASP, CWE) are standard industry resources and the provided documentation (severity guides, examples) promotes secure and accurate reporting practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:08 AM
Security Audit — agent-trust-hub — finding-writer