security-report-writer
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of Markdown documentation and templates. It contains no executable scripts (Python, JavaScript, shell), preventing risks related to remote code execution or privilege escalation.
- [DATA_EXFILTRATION]: No network operations or external URL requests were identified. The instructions emphasize secret redaction (using fingerprints) for security reporting, which aligns with safe data handling practices.
- [PROMPT_INJECTION]: Instructions focus on report structure and formatting. No bypass attempts, role-play injections, or instructions to ignore safety filters were found.
- [COMMAND_EXECUTION]: No shell commands, subprocess invocations, or dynamic command execution patterns are present.
- [EXTERNAL_DOWNLOADS]: All references point to local file paths (e.g.,
../../templates/) consistent with a structured project repository. No external dependencies or remote downloads are initiated.
Audit Metadata