Supply Chain Security
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill integrates several security tools and GitHub Actions from well-known providers. It utilizes Google's OSV-Scanner for vulnerability detection, the SLSA framework's generator for build provenance, and Sigstore's cosign for signing artifacts. It also references secret scanning tools like TruffleHog and Gitleaks. These are established services in the security community.
- [COMMAND_EXECUTION]: The instructions involve executing standard build and security commands, including
gradlewfor dependency tasks and SBOM generation,sha256sumandbase64for hashing, andcosignandgcloudfor identity and signing operations. These commands are used within their intended administrative and development context. - [PROMPT_INJECTION]: The skill processes project-level data, which represents a surface for indirect prompt injection.
- Ingestion points: Dependency lists from
gradle/libs.versions.tomland license configurations fromconfig/allowed-licenses.jsonare read into the agent's context. - Boundary markers: The provided templates do not use specific delimiters or warnings to isolate untrusted project data from instructions.
- Capability inventory: The skill has capabilities to execute shell commands (
gradlew,cosign,gcloud) and write files during the SBOM and signing process. - Sanitization: There is no explicit sanitization or validation of external dependency strings or license names before they are processed by the agent.
Audit Metadata