qa-security-testing

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and integrates multiple established security tools and GitHub Actions from well-known providers, including Semgrep, CodeQL, ZAP, Nuclei, Trivy, Checkov, and Gitleaks. These tools are recommended for standard security scanning tasks within CI/CD pipelines.
  • [COMMAND_EXECUTION]: The documentation provides numerous examples of CLI commands for running security scanners and the provided vuln_tracker.py script. These commands are essential for the skill's primary function of automating security testing.
  • [INDIRECT_PROMPT_INJECTION]: An attack surface is identified in scripts/vuln_tracker.py, which processes vulnerability data from JSON files. However, the script's capabilities are limited to data processing and report generation (printing to stdout or writing to a local file), and it lacks the ability to perform network exfiltration or execute shell commands based on the ingested content.
  • [DYNAMIC_EXECUTION]: The unit test script scripts/test_vuln_tracker.py uses the standard Python importlib library to dynamically load the target script for testing. This is a common and safe development practice for isolated unit testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — qa-security-testing