security-misconfiguration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing established security-related Python libraries and tools such as bandit, flask-talisman, secure, and defusedxml from the official PyPI registry.
- [COMMAND_EXECUTION]: The workflow involves running static analysis using bandit and search operations using grep on local application files to identify security misconfigurations. It also suggests performing dynamic scanning using an official Docker container provided by the OWASP organization.
- [INDIRECT_PROMPT_INJECTION]: As the skill is designed to audit user-provided source code, it processes external data that could theoretically contain instructions intended to influence the agent's logic, but it follows industry-standard security review workflows and practices.
Audit Metadata