Supply Chain Security

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill integrates several security tools and GitHub Actions from well-known providers. It utilizes Google's OSV-Scanner for vulnerability detection, the SLSA framework's generator for build provenance, and Sigstore's cosign for signing artifacts. It also references secret scanning tools like TruffleHog and Gitleaks. These are established services in the security community.
  • [COMMAND_EXECUTION]: The instructions involve executing standard build and security commands, including gradlew for dependency tasks and SBOM generation, sha256sum and base64 for hashing, and cosign and gcloud for identity and signing operations. These commands are used within their intended administrative and development context.
  • [PROMPT_INJECTION]: The skill processes project-level data, which represents a surface for indirect prompt injection.
  • Ingestion points: Dependency lists from gradle/libs.versions.toml and license configurations from config/allowed-licenses.json are read into the agent's context.
  • Boundary markers: The provided templates do not use specific delimiters or warnings to isolate untrusted project data from instructions.
  • Capability inventory: The skill has capabilities to execute shell commands (gradlew, cosign, gcloud) and write files during the SBOM and signing process.
  • Sanitization: There is no explicit sanitization or validation of external dependency strings or license names before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 03:36 AM
Security Audit — agent-trust-hub — Supply Chain Security