×
Third-party audit

Gen Agent Trust Hub

security-best-practices · openai/skills

High risk
Provider summary

This skill is designed for security reviews but contains a critical vulnerability to Indirect Prompt Injection. It explicitly instructs the agent to prioritize instructions found within untrusted project documentation or code comments over established security best practices. Because the skill has the capability to modify code and commit changes, an attacker could embed malicious instructions in a repository to force the agent to introduce vulnerabilities or bypass security controls during the 'Fixes' phase.

The provider classified the analyzed snapshot as HIGH risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
fail
Risk level
HIGH
Audited
Feb 15, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.