cc-skill-security-review
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is an educational resource providing security best practices, code snippets, and checklists. It contains no executable malicious code or instructions.- [CREDENTIALS_UNSAFE]: No hardcoded secrets or credentials were found. The instructions explicitly advise against hardcoding and demonstrate secure secret management using environment variables.- [PROMPT_INJECTION]: No attempts to override system prompts or bypass safety guidelines were detected. The instructional language is professional and defensive.- [EXTERNAL_DOWNLOADS]: The skill references standard security-related libraries (zod, isomorphic-dompurify, express-rate-limit, @solana/web3.js) from public registries, which is expected and appropriate for its defensive purpose.
Audit Metadata