sca-blackduck

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Downloads and executes the Synopsys Detect setup script directly from the official vendor domain (detect.synopsys.com). This is the standard, documented method for running the tool provided by the vendor.
  • [COMMAND_EXECUTION]: Executes shell commands and utilizes standard tools such as curl, bash, docker, and git to perform software dependency analysis and generate security reports.
  • [CREDENTIALS_UNSAFE]: Correctness of secret management is maintained through the use of environment variables and platform-integrated secret stores (e.g., GitHub Secrets, GitLab CI/CD Variables) rather than hardcoding credentials.
  • [EXTERNAL_DOWNLOADS]: Fetches configuration and scanning logic from well-known infrastructure and references established security databases and guidelines from NIST, CISA, and OWASP.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:00 AM
Security Audit — agent-trust-hub — sca-blackduck