discover-ai-bom

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill functions as a deterministic data processor that normalizes inventory data into the CycloneDX AI BOM format. It does not perform any state-modifying operations or unexpected cloud interactions.
  • [CREDENTIALS_UNSAFE]: The implementation includes an explicit sanitization routine that identifies and drops keys matching common secret patterns such as 'api_key', 'token', and 'password' from the generated output.
  • [DATA_EXFILTRATION]: Analysis of the source code confirms no network capabilities (e.g., requests, socket, or urllib) are present. The skill processes input via standard input or local file paths and outputs strictly to the console or a designated local file.
  • [COMMAND_EXECUTION]: The skill uses Python standard library modules for JSON parsing and UUID generation; it does not utilize the 'os.system', 'subprocess', or 'eval' functions to execute arbitrary commands or code.
  • [EXTERNAL_DOWNLOADS]: No external package dependencies are required, and the skill does not fetch remote scripts or configuration files during execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — discover-ai-bom