sast-orchestrator
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious patterns, prompt injections, or data exfiltration attempts were detected. The skill adheres to security best practices for triaging and configuring static analysis tools.
- [EXTERNAL_DOWNLOADS]: The skill references several official and well-known software repositories and documentation sites, including GitHub, Semgrep, and SonarSource. These are considered trusted sources for security tooling.
- [COMMAND_EXECUTION]: The skill provides example shell commands and GitHub Actions workflows for running SAST scanners. These commands are standard for the intended purpose of automating security checks in a development environment and do not involve suspicious execution patterns.
Audit Metadata