ops-sam-gov

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with official government endpoints (api.sam.gov and api-alpha.sam.gov). Network operations are restricted to these domains and are used to fetch public contractor and solicitation data.\n- [SAFE]: API authentication is handled through the SAMGOV_API_KEY environment variable or a local .env file. No hardcoded credentials were found within the skill files.\n- [SAFE]: The skill has a theoretical surface for indirect prompt injection as it ingests data from SAM.gov into the agent's context. However, the risk is mitigated by the trusted nature of the government-managed API. Evidence chain: 1) Ingestion point: sam_gov_ops.py (API responses). 2) Boundary markers: Absent in console output. 3) Capability inventory: Bash, Read, and Write tools. 4) Sanitization: API strings are processed for display without specific character filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ops-sam-gov