secure-code-review
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is configured with a restricted toolset consisting only of read-only filesystem tools (Read, Grep, Glob), which prevents the agent from executing reviewed code or performing unauthorized network operations.
- [SAFE]: A dedicated 'Prompt Injection Safety Notice' provides robust instructions for the agent to treat all reviewed content as inert text and to ignore any instructions or directives embedded within code comments or logic.
- [SAFE]: No hardcoded credentials, malicious persistence mechanisms, or unauthorized remote code execution patterns were found. Code snippets containing secrets or dangerous functions are clearly labeled as vulnerable examples for educational and detection purposes.
- [SAFE]: All external links point to trusted security organizations and well-known services, including OWASP, NIST, and Microsoft's official documentation.
- [SAFE]: The skill establishes clear trust boundaries and adheres to the principle of least privilege by limiting its own capabilities to static analysis.
Audit Metadata