cspt

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a purely educational resource focused on web security auditing. It describes technical concepts related to Client-Side Path Traversal and provides legitimate remediation patterns like using encodeURIComponent().
  • [OBFUSCATION]: The file contains URL-encoded strings such as %2e%2e/ and %252f. These are presented as educational examples of WAF bypass payloads for security testing rather than attempts to obfuscate the skill's own internal logic or commands. These are benign in the context of a security research guide.
  • [COMMAND_EXECUTION]: The skill suggests using standard Unix utilities like grep to search source code for vulnerable patterns. These commands are intended for manual execution by a developer or security auditor to inspect local files and do not represent malicious or automated execution of harmful code.
  • [EXTERNAL_DOWNLOADS]: The skill links to a technical blog post (matanber.com/blog/cspt-levels) as a source of information. This is a legitimate reference to security research and does not involve automated downloading or execution of remote scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:35 PM
Security Audit — agent-trust-hub — cspt