appsec-owasp

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a directory listing command (ls) to identify whether recommended companion skills are already installed in standard platform directories. This is a benign discovery mechanism used solely to offer relevant tool installations for a complete security workflow.
  • [EXTERNAL_DOWNLOADS]: The documentation and code examples reference several industry-standard and trusted Node.js security libraries, including helmet, zod, dompurify, and bcrypt. The skill also provides an installation instruction using the npx package runner to fetch the skill itself from its official repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 03:03 PM
Security Audit — agent-trust-hub — appsec-owasp