codeql-security-scanner
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions utilize official CodeQL CLI command patterns for database creation and analysis. All shell commands are consistent with the stated purpose of performing local code security assessments.
- [SAFE]: The workflow includes explicit security boundaries, specifically advising against uploading SARIF reports from private codebases without proper authorization.
- [SAFE]: All external resource references point to official GitHub and CodeQL documentation domains. No unauthorized remote code execution or exfiltration patterns were detected.
Audit Metadata