grype
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the installation script for
syftfrom the official GitHub repository of Anchore, a well-known technology provider in the security space.\n- [REMOTE_CODE_EXECUTION]: Instructs the execution of thesyftinstallation script directly via shell pipe (curl | sh) within the reference documentation.\n- [CREDENTIALS_UNSAFE]: Contains hardcoded placeholder credentials (mypassword,my_token) in the example configuration file located inreferences/config-ignore.md.\n- [COMMAND_EXECUTION]: Executes thegrypeCLI tool to scan local filesystem paths, container images, and SBOM files for vulnerabilities.\n- [PROMPT_INJECTION]: The skill possesses a potential attack surface for indirect prompt injection as it ingests untrusted data from external container images and filesystems (found inSKILL.md) and processes it using shell-based tools (grype,jq) without explicit output sanitization or boundary markers.
Audit Metadata