agent-bom-ingest
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
agent-bomCLI tool to perform validation and scanning of inventory JSON files provided by the operator. - [EXTERNAL_DOWNLOADS]: Communicates with well-known security services including
api.osv.devandapi.github.comto fetch vulnerability information and advisory data. - [DATA_EXFILTRATION]: Supports an optional push of processed inventory data to a control plane URL explicitly provided by the operator via the
AGENT_BOM_PUSH_URLenvironment variable. - [SAFE]: Ingests untrusted data from local inventory JSON files.
- Ingestion points: Inventory JSON files selected by the operator for processing.
- Boundary markers: Uses mandatory schema validation against
inventory.schema.jsonto verify data integrity before ingestion. - Capability inventory: Involves local file reading, execution of the
agent-bombinary, and network operations to vulnerability databases and user-defined endpoints. - Sanitization: Includes a built-in sanitizer and redaction contract to ensure sensitive credentials like API keys or private tokens are not exposed in outputs or exports.
Audit Metadata