supply-chain-security-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains command-line templates for security auditing tools like Syft, Grype, and Cosign. These commands are intended for the primary purpose of vulnerability management and build integrity verification, performed via a restricted shell environment.
- [INDIRECT_PROMPT_INJECTION]: The skill involves processing external data sources such as dependency lockfiles and Software Bill of Materials (SBOM) documents, which presents a surface for indirect prompt injection. 1. Ingestion points: Security scanner inputs and dependency manifests (SKILL.md, references/RESPONSE.md). 2. Boundary markers: Relies on the agent's default processing; no specific prompt delimiters are implemented in the instructional content. 3. Capability inventory: Includes the Bash tool for running scanners, package managers, and container tools (SKILL.md). 4. Sanitization: Recommends disabling package install scripts (ignore-scripts=true) to prevent execution of malicious code during the dependency resolution phase.
- [SAFE]: The skill exclusively promotes security best practices, including verifiable dependencies, signed provenance, and least-privilege CI/CD configurations. It utilizes trusted tools and does not contain any obfuscated code, unauthorized data exfiltration patterns, or persistence mechanisms.
Audit Metadata