pre-launch-security-audit

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate security auditing tool with no malicious patterns detected. Its purpose is to improve application security through structured review.
  • [PROMPT_INJECTION]: The skill does not contain instructions that attempt to bypass safety filters or override agent constraints. The risk of indirect prompt injection is acknowledged as the skill processes untrusted project files, but it is mitigated by instructions to verify all findings with concrete evidence. Ingestion points: Project source code and repository configuration files as described in SKILL.md. Boundary markers: No explicit input delimiters, though reliance on verified evidence serves as a procedural boundary. Capability inventory: Execution of local project scanners. Sanitization: None specified.
  • [DATA_EXFILTRATION]: There are no indicators of data exfiltration or hardcoded credentials. The skill explicitly guides the agent to identify and rotate exposed secrets within the target application.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or untrusted dependency downloads were identified. The skill references the use of standard security scanners already present in a project environment but does not execute unverified remote scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 11:02 AM
Security Audit — agent-trust-hub — pre-launch-security-audit