security-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a standard security auditing workflow for reviewing code changes. It identifies high-risk areas, suggests verification tools, and outlines threat modeling steps. No malicious behavior or suspicious patterns were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external, potentially untrusted application code and repository changes. 1. Ingestion points: Identifying changed files and reviewing security-sensitive surfaces in the codebase (SKILL.md). 2. Boundary markers: The instructions do not specify explicit delimiters or warnings for the agent. 3. Capability inventory: The skill suggests using CLI tools for verification such as npm audit, semgrep, gitleaks, and trivy (SKILL.md). 4. Sanitization: No explicit sanitization or filtering of the code content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:57 AM
Security Audit — agent-trust-hub — security-auditor