secure

Pass

Audited by Gen Agent Trust Hub on Feb 19, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION] (LOW): The skill contains shell script snippets (e.g., grep -r "api_key" src/ and loops using curl) designed for local security testing. These are intended for the user to verify their own application's security posture and do not pose a risk of unauthorized command execution.
  • [DATA_EXPOSURE] (SAFE): The content explicitly warns against hardcoding credentials and provides clear instructions for using environment variables and .gitignore to protect sensitive data.
  • [REMOTE_CODE_EXECUTION] (SAFE): No remote code execution patterns were detected. The skill recommends standard, well-known libraries like bcrypt and helmet.js for security purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 19, 2026, 08:27 PM