skills/aeondave/malskill/grype/Gen Agent Trust Hub

grype

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the installation script for syft from the official GitHub repository of Anchore, a well-known technology provider in the security space.\n- [REMOTE_CODE_EXECUTION]: Instructs the execution of the syft installation script directly via shell pipe (curl | sh) within the reference documentation.\n- [CREDENTIALS_UNSAFE]: Contains hardcoded placeholder credentials (mypassword, my_token) in the example configuration file located in references/config-ignore.md.\n- [COMMAND_EXECUTION]: Executes the grype CLI tool to scan local filesystem paths, container images, and SBOM files for vulnerabilities.\n- [PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection as it ingests untrusted data from external container images and filesystems (found in SKILL.md) and processes it using shell-based tools (grype, jq) without explicit output sanitization or boundary markers.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 09:17 AM
Security Audit — agent-trust-hub — grype