supply-chain-security-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains command-line templates for security auditing tools like Syft, Grype, and Cosign. These commands are intended for the primary purpose of vulnerability management and build integrity verification, performed via a restricted shell environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing external data sources such as dependency lockfiles and Software Bill of Materials (SBOM) documents, which presents a surface for indirect prompt injection. 1. Ingestion points: Security scanner inputs and dependency manifests (SKILL.md, references/RESPONSE.md). 2. Boundary markers: Relies on the agent's default processing; no specific prompt delimiters are implemented in the instructional content. 3. Capability inventory: Includes the Bash tool for running scanners, package managers, and container tools (SKILL.md). 4. Sanitization: Recommends disabling package install scripts (ignore-scripts=true) to prevent execution of malicious code during the dependency resolution phase.
  • [SAFE]: The skill exclusively promotes security best practices, including verifiable dependencies, signed provenance, and least-privilege CI/CD configurations. It utilizes trusted tools and does not contain any obfuscated code, unauthorized data exfiltration patterns, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — supply-chain-security-expert