poam-automation-expert

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the use of a Python CLI tool for automating compliance reports. It interacts with well-known security services, including the CISA Known Exploited Vulnerabilities (KEV) catalog and the First.org EPSS API, to enrich vulnerability data.
  • [SAFE]: The skill requires the 'openpyxl' Python package for generating Excel-based VDR reports, which is a standard industry library for spreadsheet manipulation.
  • [SAFE]: The skill processes external data from vulnerability scanners (Nessus, Tenable, Qualys, Wiz). While this represents an ingestion point for untrusted data (Indirect Prompt Injection surface), it is the primary intended purpose of the GRC tool and is handled as structured data for compliance reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:26 PM
Security Audit — agent-trust-hub — poam-automation-expert