security-patterns
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as an educational resource for application security, providing code examples and architectural guidance.
- [PROMPT_INJECTION]: Mentions of instruction-override phrases (e.g., "ignore previous rules") are used strictly as illustrative examples of adversarial inputs that developers should defend against in their own applications. They do not constitute an attempt to manipulate the agent's behavior.
- [CREDENTIALS_UNSAFE]: Code examples for environment variables and authentication use standard placeholders (e.g., "postgresql://...", "your-secret-here") rather than real secrets or sensitive data.
- [EXTERNAL_DOWNLOADS]: The skill references well-known and trusted security libraries (e.g., bcrypt, argon2, pydantic, slowapi) in code snippets for demonstration purposes. It also recommends the use of Yelp's 'detect-secrets' tool, which is a reputable open-source security tool.
Audit Metadata