net-auth-audit

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a legitimate utility for performing security audits on .NET applications. It incorporates a structured workflow that requires the agent to verify authentication and authorization logic across multiple layers, including global filters, middleware, and resource-level checks. It explicitly prohibits destructive Proof-of-Concept (PoC) actions and requires evidence-backed conclusions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external untrusted data, such as project source code, configuration files, and decompiled binary artifacts. This creates an inherent surface for indirect prompt injection where malicious instructions could be embedded in the audited code to deceive the auditor. The skill mitigates this risk through its core rules, which mandate a strict evidence chain, require cross-referencing of global security configurations, and warn against relying on easily manipulated front-end indicators.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 04:28 AM
Security Audit — agent-trust-hub — net-auth-audit