Security Engineer
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions do not contain any malicious patterns, obfuscation, or attempts to exfiltrate data. It focuses on defensive security engineering and follows best practices such as STRIDE threat modeling and OWASP guidelines.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, specifically source code and infrastructure configurations, which is an inherent risk for indirect prompt injection. However, this is consistent with the primary purpose of a security auditing tool.
- Ingestion points:
SKILL.md(Workflow Phase 1: Reconnaissance & Threat Modeling, Phase 2: Security Assessment). - Boundary markers: The instructions do not define specific delimiters for separating analyzed code from agent instructions.
- Capability inventory: The skill instructions do not invoke dangerous system-level commands or unauthorized network operations.
- Sanitization: There are no instructions for sanitizing or escaping content from external files before analysis.
Audit Metadata