sast-config

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized behaviors were detected in the skill instructions or metadata.
  • [PROMPT_INJECTION]: The skill contains a safety notice specifically instructing the agent to treat data within SAST rules as untrusted content, demonstrating a proactive defense against indirect prompt injection.
  • [EXTERNAL_DOWNLOADS]: Mentions of official tool containers and GitHub Actions (e.g., Semgrep and CodeQL) are restricted to educational examples and target well-known, trusted services.
  • [COMMAND_EXECUTION]: The skill correctly limits its operations to safe-by-default tools such as Read, Grep, and Glob, ensuring it only analyzes and does not execute the files it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — sast-config