cmmc-assessor
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's code and instructions are entirely consistent with its stated purpose as a compliance assessment tool. No obfuscation, data exfiltration, or malicious persistence mechanisms were detected.
- [COMMAND_EXECUTION]: The skill uses the Python
subprocessmodule to execute local system commands includingsystemctl(to check service status),lsblk(to check for LUKS encryption), andnft(to verify firewall rules). All executed commands use hardcoded arguments or are limited to safe diagnostic operations. - [EXTERNAL_DOWNLOADS]: The skill defines standard dependencies in its
pyproject.toml, includingtyper,httpx, andpyyaml. These are well-known, reputable libraries from official package registries.
Audit Metadata