supply-chain-security

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • Reference-Only Content: The skill is composed exclusively of reference documentation and taxonomies designed to assist in manual or guided security assessments. It does not include any active scripts, executables, or automation logic.
  • Standard Catalog Integration: The content correctly attributes and references established industry standards from well-known organizations such as the OpenSSF, SLSA, and Sigstore. All external links point to official documentation and repositories.
  • Assessment Framework: The skill provides a protocol for assessing repository posture (Detect, Classify, Document, Verify) but relies on the user or the agent's existing capabilities to perform these actions without introducing new external dependencies or remote code execution vectors.
  • Vendor-Specific Context: The references to specific toolchains (hve-core and physical-ai-toolchain) serve as implementation examples within the author's internal security framework and do not involve unauthorized data access or credential handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 06:10 PM
Security Audit — agent-trust-hub — supply-chain-security