skills/aeondave/malskill/trivy/Gen Agent Trust Hub

trivy

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous templates for executing shell commands via the trivy CLI tool. These commands interact with the local filesystem, remote repositories, and Kubernetes clusters.
  • Evidence: trivy image <image>, trivy fs <path>, trivy repo <url>, and trivy k8s commands documented throughout SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external sources (remote git repositories, container images, and local files) which is then processed by the Trivy scanner. Malicious instructions could be embedded in scanned metadata or source code to influence the agent's interpretation of the scan results.
  • Ingestion points: Commands like trivy repo https://github.com/org/project and trivy fs /path/to/code in SKILL.md ingest external content.
  • Boundary markers: None. The skill does not provide specific instructions to delimit or ignore instructions within the scanned content.
  • Capability inventory: The skill uses subprocess calls to execute trivy binaries across all documented workflows in SKILL.md and references/container-security.md.
  • Sanitization: None. The skill does not implement validation or filtering of the external content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:41 PM
Security Audit — agent-trust-hub — trivy