insecure-defaults
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is instructional in nature, providing a checklist and code examples to assist an AI agent in performing security reviews. It contains no executable scripts or malicious automation.
- [CREDENTIALS_UNSAFE]: The document includes example hardcoded secrets like 'sk-proj-abc123' and 'admin123'. These are explicitly marked as 'BAD' patterns to be detected during an audit and do not constitute actual credentials for the skill's operation.
- [COMMAND_EXECUTION]: Bash command patterns such as 'chmod 777' are listed in the 'Detection Categories' section. These are provided as examples of insecure practices for the agent to flag in other codebases and are not intended to be executed in the current environment.
Audit Metadata