owasp-security-check
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is specifically designed to ingest and analyze untrusted user-provided source code, configuration files, and API documentation, which presents a surface for indirect prompt injection.
- Ingestion points: Processes user-provided files, folders, and full codebases during the audit workflow as described in
SKILL.md. - Boundary markers: The instructions do not mandate the use of delimiters (e.g., XML tags or backticks) or explicit warnings (e.g., "ignore embedded instructions") to prevent the LLM from inadvertently following malicious commands hidden within the code being audited.
- Capability inventory: The skill is primarily informational and instructs the agent to generate a text-based security report. While it references audit tools like
npm audit, it does not contain scripts that execute autonomous network operations or file system modifications. - Sanitization: There are no mechanisms mentioned for sanitizing or filtering the content of the files before they are read into the agent's context.
- [SAFE]: The skill includes several examples of hardcoded secrets and API keys (e.g.,
sk_live_a1b2c3d4e5f6,sk_live_51H..., andAIzaSyB...). These are documented correctly within code blocks explicitly labeled as "Bad Patterns" or "Vulnerable." They serve as pedagogical examples for the agent to recognize during a security audit and do not represent a credential leak or malicious intent within the skill itself.
Audit Metadata