discover-control-evidence
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The Python script src/discover.py performs deterministic data transformations on JSON input artifacts (CycloneDX AI BOMs or environment graphs). It adheres to a read-only model, using standard library modules for IO and structural validation without any risky operations such as subprocess execution or network access.
- [SAFE]: A built-in sanitization mechanism (_sanitize) proactively identifies and removes sensitive information, such as API keys and credentials, based on a broad keyword list before any evidence is generated or output.
- [SAFE]: All external references in REFERENCES.md point to authoritative industry standards and official documentation from trusted organizations including NIST, MITRE, and the PCI Security Standards Council.
- [SAFE]: The skill contains no evidence of prompt injection, obfuscation, persistence, or privilege escalation. Its behavior is consistent with its stated purpose as a security audit support tool.
Audit Metadata