skills/semgrep/skills/llm-security/Gen Agent Trust Hub

llm-security

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECREDENTIALS_UNSAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes multiple code snippets that demonstrate insecure coding practices to provide educational contrast. These snippets contain hardcoded strings representing example database credentials and API keys. Examples include 'postgresql://admin:SuperSecret123@db.internal.acme.com/prod' in rules/system-prompt-leakage.md and 'sk-abc123secretkey456' in rules/sensitive-disclosure.md and AGENTS.md. These are considered safe in context because they are explicitly part of 'Vulnerable' code blocks intended for learning and use obviously generic or placeholder values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:49 AM
Security Audit — agent-trust-hub — llm-security