cve-triage

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill definition is purely instructional and does not contain any malicious patterns, obfuscation, or unauthorized access attempts. It describes a standard professional workflow for security analysis.
  • [NO_CODE]: The analyzed content is limited to markdown documentation. There are no associated scripts, binaries, or automated shell commands provided that could execute logic on the host system.
  • [PROMPT_INJECTION]: The skill describes a process that ingests external, untrusted data (CVE reports and advisories), which is a common surface for indirect prompt injection.
  • Ingestion points: The 'CVE Intake' phase in SKILL.md identifies CVE identifiers and advisory details as inputs.
  • Boundary markers: The workflow description does not specify delimiters or boundary markers for external data.
  • Capability inventory: The process involves code analysis using grep and CodeQL (Phase 2) and reproduction assessment (Phase 3).
  • Sanitization: No explicit sanitization or filtering logic is mentioned in the workflow overview.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 12:59 PM
Security Audit — agent-trust-hub — cve-triage