sbom-syft

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading security utilities such as cosign and tfsec. These resources are fetched from established GitHub organizations (sigstore, aquasecurity), which are recognized as well-known services.
  • [COMMAND_EXECUTION]: Core functionality is achieved through the execution of CLI tools (syft, grype, cosign, docker, jq) used to process container images and filesystems for package metadata extraction and vulnerability analysis.
  • [SAFE]: The skill includes comprehensive templates for secure CI/CD pipelines and security detection rules. Potential sensitive patterns, such as placeholder credentials or vulnerable code snippets in the templates, are used exclusively for educational purposes and are explicitly identified as examples of insecure patterns to avoid.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:00 AM
Security Audit — agent-trust-hub — sbom-syft