sast-orchestrator

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, prompt injections, or data exfiltration attempts were detected. The skill adheres to security best practices for triaging and configuring static analysis tools.
  • [EXTERNAL_DOWNLOADS]: The skill references several official and well-known software repositories and documentation sites, including GitHub, Semgrep, and SonarSource. These are considered trusted sources for security tooling.
  • [COMMAND_EXECUTION]: The skill provides example shell commands and GitHub Actions workflows for running SAST scanners. These commands are standard for the intended purpose of automating security checks in a development environment and do not involve suspicious execution patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:30 PM
Security Audit — agent-trust-hub — sast-orchestrator