agent-bom-vulnerability-intel
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches security advisory data from well-known and reputable sources including Google's OSV (api.osv.dev), GitHub Security Advisories, NIST's National Vulnerability Database, First.org (EPSS), and CISA. These are standard resources for vulnerability research and are considered safe sources.
- [COMMAND_EXECUTION]: Utilizes the agent-bom CLI tool to process SBOMs and inventory files. All commands are restricted to checking identifiers against advisory databases, following the intended purpose of the skill.
- [DATA_EXFILTRATION]: Transmits package identifiers to external security databases. The skill includes specific guardrails, such as 'explain-only' and 'offline-review' modes, to ensure transparency and allow the operator to control what data leaves the environment.
- [CREDENTIALS_UNSAFE]: Explicitly manages optional environment tokens (NVD_API_KEY, GITHUB_TOKEN) with instructions to never display, log, or reveal these values in prompts or exported reports.
Audit Metadata