sast-configuration
Pass
Audited by Gen Agent Trust Hub on Feb 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or security vulnerabilities were identified. The skill adheres to its stated purpose of configuring security scanning tools.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing and using tools from well-known and trusted sources. This includes the Semgrep CLI via pip, the CodeQL extension for the GitHub CLI, and official Semgrep GitHub Actions.\n- [COMMAND_EXECUTION]: Standard command-line examples are provided for initializing security tools and running Docker containers, all of which are appropriate for the tool's intended use in a development or security testing environment.
Audit Metadata