attack-surface-test-checklist

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill logic is instructional and follows established security analysis practices for generating test plans based on modified attack surfaces.
  • [EXTERNAL_DOWNLOADS]: The skill includes numerous links to official documentation from the OWASP Foundation (e.g., owasp.org and github.com/OWASP/ASVS). These are recognized as well-known, trusted resources for security standards and are used correctly for documentation purposes.
  • [PROMPT_INJECTION]: No patterns associated with system instruction overrides, safety filter bypasses, or DAN-style personas were detected. The skill maintains a consistent technical and professional tone.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external code diffs and change sets to produce its output.
  • Ingestion points: The skill analyzes file paths and code content as specified in the classification signals table in SKILL.md.
  • Boundary markers: The skill specifies a structured Markdown output format with a defined header and footer, providing a logical boundary for agent operations.
  • Capability inventory: The skill logic is limited to classification and text generation; it does not invoke tools for external network access or filesystem modification.
  • Sanitization: Not explicitly implemented, but the risk is mitigated by the skill's specific, non-executable purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:52 AM
Security Audit — agent-trust-hub — attack-surface-test-checklist