authoring-security-skills

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and procedural guidelines for contributing new security-focused skills to a specific repository. It includes instructions for categorization, metadata creation, and local validation using standard scripts. No malicious patterns, data exfiltration, or safety bypasses were identified.
  • [COMMAND_EXECUTION]: The skill documents standard shell commands for repository maintenance, such as python3 scripts/sync_attack.py --write. These are local operations consistent with the skill's primary purpose of repository management and do not involve untrusted input or remote code execution.
  • [DATA_EXFILTRATION]: The skill references various configuration and metadata files (e.g., ttp-index.json, cases.jsonl, plugin.json). These are standard project files used for mapping techniques and do not contain sensitive credentials or private user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 11:27 AM
Security Audit — agent-trust-hub — authoring-security-skills