supply-chain-security
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFENO_CODE
Full Analysis
- Reference-Only Content: The skill is composed exclusively of reference documentation and taxonomies designed to assist in manual or guided security assessments. It does not include any active scripts, executables, or automation logic.
- Standard Catalog Integration: The content correctly attributes and references established industry standards from well-known organizations such as the OpenSSF, SLSA, and Sigstore. All external links point to official documentation and repositories.
- Assessment Framework: The skill provides a protocol for assessing repository posture (Detect, Classify, Document, Verify) but relies on the user or the agent's existing capabilities to perform these actions without introducing new external dependencies or remote code execution vectors.
- Vendor-Specific Context: The references to specific toolchains (hve-core and physical-ai-toolchain) serve as implementation examples within the author's internal security framework and do not involve unauthorized data access or credential handling.
Audit Metadata