trivy
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous templates for executing shell commands via the
trivyCLI tool. These commands interact with the local filesystem, remote repositories, and Kubernetes clusters. - Evidence:
trivy image <image>,trivy fs <path>,trivy repo <url>, andtrivy k8scommands documented throughoutSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources (remote git repositories, container images, and local files) which is then processed by the Trivy scanner. Malicious instructions could be embedded in scanned metadata or source code to influence the agent's interpretation of the scan results.
- Ingestion points: Commands like
trivy repo https://github.com/org/projectandtrivy fs /path/to/codeinSKILL.mdingest external content. - Boundary markers: None. The skill does not provide specific instructions to delimit or ignore instructions within the scanned content.
- Capability inventory: The skill uses subprocess calls to execute
trivybinaries across all documented workflows inSKILL.mdandreferences/container-security.md. - Sanitization: None. The skill does not implement validation or filtering of the external content before processing.
Audit Metadata