cwe-643-xpath-injection
Pass
Audited by Gen Agent Trust Hub on Mar 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill content is informational and focuses on improving code security. No malicious patterns were detected in the instructions or examples.
- [COMMAND_EXECUTION]: The skill provides a benign shell command (grep) for developers to locate vulnerable patterns in local Java files. This command is restricted to search operations and does not represent a threat.
Audit Metadata