qa-security-testing
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and integrates multiple established security tools and GitHub Actions from well-known providers, including Semgrep, CodeQL, ZAP, Nuclei, Trivy, Checkov, and Gitleaks. These tools are recommended for standard security scanning tasks within CI/CD pipelines.
- [COMMAND_EXECUTION]: The documentation provides numerous examples of CLI commands for running security scanners and the provided
vuln_tracker.pyscript. These commands are essential for the skill's primary function of automating security testing. - [INDIRECT_PROMPT_INJECTION]: An attack surface is identified in
scripts/vuln_tracker.py, which processes vulnerability data from JSON files. However, the script's capabilities are limited to data processing and report generation (printing to stdout or writing to a local file), and it lacks the ability to perform network exfiltration or execute shell commands based on the ingested content. - [DYNAMIC_EXECUTION]: The unit test script
scripts/test_vuln_tracker.pyuses the standard Pythonimportliblibrary to dynamically load the target script for testing. This is a common and safe development practice for isolated unit testing.
Audit Metadata