sast-config
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized behaviors were detected in the skill instructions or metadata.
- [PROMPT_INJECTION]: The skill contains a safety notice specifically instructing the agent to treat data within SAST rules as untrusted content, demonstrating a proactive defense against indirect prompt injection.
- [EXTERNAL_DOWNLOADS]: Mentions of official tool containers and GitHub Actions (e.g., Semgrep and CodeQL) are restricted to educational examples and target well-known, trusted services.
- [COMMAND_EXECUTION]: The skill correctly limits its operations to safe-by-default tools such as Read, Grep, and Glob, ensuring it only analyzes and does not execute the files it processes.
Audit Metadata