cmmc-assessor

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's code and instructions are entirely consistent with its stated purpose as a compliance assessment tool. No obfuscation, data exfiltration, or malicious persistence mechanisms were detected.
  • [COMMAND_EXECUTION]: The skill uses the Python subprocess module to execute local system commands including systemctl (to check service status), lsblk (to check for LUKS encryption), and nft (to verify firewall rules). All executed commands use hardcoded arguments or are limited to safe diagnostic operations.
  • [EXTERNAL_DOWNLOADS]: The skill defines standard dependencies in its pyproject.toml, including typer, httpx, and pyyaml. These are well-known, reputable libraries from official package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — cmmc-assessor