owasp-top-10-web
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for security auditing and follows best practices for its intended purpose. All provided patterns and instructions are for analysis and documentation of common security vulnerabilities.
- [PROMPT_INJECTION]: While the skill ingests untrusted code for analysis, it explicitly includes a 'Prompt Injection Safety Notice' that instructs the agent to treat all code as data and ignore any embedded directives. Ingestion points: Source code and configuration files accessed via Glob, Grep, and Read (SKILL.md). Boundary markers: Dedicated safety notice instructing the agent to treat code as data and ignore instructions in reviewed files (SKILL.md). Capability inventory: Limited to read-only tools (Read, Grep, Glob). No tools for network communication, file system modifications, or code execution are enabled (SKILL.md). Sanitization: Explicit instructions to ignore any content in analyzed files that attempts to override agent rules or behavior (SKILL.md).
Audit Metadata