skills/semgrep/skills/code-security/Gen Agent Trust Hub

code-security

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation-based resource for security guidelines. All code patterns that would typically be flagged as dangerous, such as eval() or hardcoded secrets, are contained within 'Incorrect' code blocks intended to teach agents how to identify and prevent such vulnerabilities.
  • [CREDENTIALS_UNSAFE]: Multiple rule files (e.g., rules/secrets.md) contain hardcoded dummy credentials and API keys. These are part of 'Incorrect' examples to illustrate the risk of hardcoding secrets and do not represent actual leaked credentials.
  • [DYNAMIC_EXECUTION]: Rule files like rules/code-injection.md contain examples of eval() and exec(). These are used to demonstrate vulnerabilities and provide secure alternatives, adhering to the skill's purpose as a security training resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:30 AM
Security Audit — agent-trust-hub — code-security